PT-2024-35797 · Unknown · Phpgurukul Covid19 Testing Management System

Published

2024-11-27

·

Updated

2024-11-27

·

CVE-2024-53635

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul COVID 19 Testing Management System version 1.0
Description A Reflected Cross Site Scripting (XSS) issue was found in the /covid-tms/patient-search-report.php endpoint, which allows remote attackers to execute arbitrary code via the searchdata POST request parameter.
Recommendations For PHPGurukul COVID 19 Testing Management System version 1.0, consider disabling the searchdata parameter in the /covid-tms/patient-search-report.php endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-53635

Affected Products

Phpgurukul Covid19 Testing Management System