Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-27744. PoCs published by Shubham Pandey, shubham-s-pandey.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Petrol Pump Management Software v1.0 by uploading a malicious SVG file containing JavaScript code. The payload executes when the SVG is rendered, triggering an alert dialog.
Description
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in Petrol Pump Management Software v1.0 by uploading a malicious SVG file containing JavaScript code. The payload executes when the SVG is rendered, triggering an alert dialog.
The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-27744, describing XSS vulnerabilities in Petrol Pump Management Software v1.0. The writeups include attack vectors, affected components, and payload examples, demonstrating a clear understanding of the vulnerabilities.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N