PT-2024-39555 · Sourcecodester · Sourcecodester Online Railway Reservation System

Guru

·

Published

2024-09-28

·

Updated

2024-10-01

·

CVE-2024-9300

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Online Railway Reservation System version 1.0
Description A problematic issue was found in the Message Us Form component, specifically in the contact us.php file. The manipulation of the fullname, email, or message arguments leads to cross-site scripting. This issue can be initiated remotely.
Recommendations For SourceCodester Online Railway Reservation System version 1.0, consider validating and sanitizing user input for the fullname, email, and message arguments in the contact us.php file to prevent cross-site scripting attacks. As a temporary workaround, restrict access to the Message Us Form component until a proper fix is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-9300

Affected Products

Sourcecodester Online Railway Reservation System