PT-2024-25197 · Sourcecodester · Sourcecodester Computer Laboratory Management System

Published

2024-05-01

·

Updated

2024-05-02

·

CVE-2024-33307

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Laboratory Management System version 1.0
Description The issue is related to Cross Site Scripting (XSS) via the Last Name parameter in the Create User function. This allows for potential malicious script injection.
Recommendations For SourceCodester Laboratory Management System version 1.0, as a temporary workaround, consider restricting the input for the Last Name parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-33307

Affected Products

Sourcecodester Computer Laboratory Management System