github.comexploit
https://github.com/YasserREED/YasserREED-CVEs/blob/main/Best%20house%20rental%20management%20system%20project%20in%20php/Stored%20Cross-Site%20Scripting%20(XSS).md CVE-2024-11742
MEDIUM
SourceCodester Best House Rental Management System ajax.php cross site scripting
Record summary
CVE-2024-11742 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management System 1.0. This issue affects some unknown processing of the file /rental/ajax.php?action=save_tenant. The manipulation of the argument lastname/firstname/middlename leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 26, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Best House Rental Management SystemBrowse SourceCodester / Best House Rental Management SystemDefault status: unknown | CVE List | 1.0 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-11742 VDB-286139 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.286139 VDB-286139 | SourceCodester Best House Rental Management System ajax.php cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.286139 Submit #449683 | sourcecodester Best house rental management system project in php v1.0 Stored Cross-Site Scripting (XSS)Third-party advisory
https://vuldb.com/?submit.449683 sourcecodester.comproduct
https://www.sourcecodester.com/