Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-27743. PoCs published by Shubham Pandey, shubham-s-pandey.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Petrol Pump Management Software v1.0 via the 'Address' parameter in add_invoices.php. The payload is stored and executed when viewing the manage_invoices.php page.
Description
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component.
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in Petrol Pump Management Software v1.0 via the 'Address' parameter in add_invoices.php. The payload is stored and executed when viewing the manage_invoices.php page.
The repository contains detailed technical writeups for multiple CVEs, including XSS, SQL injection, and file upload vulnerabilities in Petrol Pump Management Software and Employee Management System. Each writeup provides specific attack vectors, affected components, and payload examples.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N