PT-2024-35797 · Unknown · Phpgurukul Covid19 Testing Management System

CVE-2024-53635

·

Published

2024-11-27

·

Updated

2024-11-27

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul COVID 19 Testing Management System version 1.0
Description A Reflected Cross Site Scripting (XSS) issue was found in the /covid-tms/patient-search-report.php endpoint, which allows remote attackers to execute arbitrary code via the searchdata POST request parameter.
Recommendations For PHPGurukul COVID 19 Testing Management System version 1.0, consider disabling the searchdata parameter in the /covid-tms/patient-search-report.php endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-53635

Affected Products

Phpgurukul Covid19 Testing Management System