PT-2024-34436 · Unknown · Kashipara E-Learning Management System Project

·

CVE-2024-50838

·

Published

2024-11-14

·

Updated

2024-11-15

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: KASHIPARA E-learning Management System Project version 1.0
Description: A Stored Cross-Site Scripting (XSS) issue was discovered in the /admin/department.php file. This allows remote attackers to execute arbitrary scripts via the d and pi parameters.
Recommendations: For KASHIPARA E-learning Management System Project version 1.0, consider restricting access to the /admin/department.php file until a fix is available, and avoid using the d and pi parameters in this context to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50838

Affected Products

Kashipara E-Learning Management System Project