PT-2024-31256 · Unknown · Phpgurukul Bus Pass Management System
Shouvik Dutta
+1
·
Published
2024-09-13
·
Updated
2024-09-16
·
CVE-2024-44798
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
phpgurukul Bus Pass Management System version 1.0
Description
The issue is a Cross-site scripting (XSS) vulnerability found in the /admin/pass-bwdates-reports-details.php file via
fromdate and todate parameters. This allows for potential malicious script injection.Recommendations
For phpgurukul Bus Pass Management System version 1.0, consider disabling access to the /admin/pass-bwdates-reports-details.php file until a patch is available. As a temporary workaround, restrict the use of the
fromdate and todate parameters in the affected API endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Bus Pass Management System