CVE-2024-27744

MEDIUM

Petrol Pump Mangement Software v.1.0 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-27744. PoCs published by Shubham Pandey, shubham-s-pandey.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Petrol Pump Management Software v1.0 by uploading a malicious SVG file containing JavaScript code. The payload executes when the SVG is rendered, triggering an alert dialog.

Description

Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.

Exploits (2)

exploitdb WORKING POC
by Shubham Pandey · textremotephp
https://www.exploit-db.com/exploits/51837

This exploit demonstrates a stored XSS vulnerability in Petrol Pump Management Software v1.0 by uploading a malicious SVG file containing JavaScript code. The payload executes when the SVG is rendered, triggering an alert dialog.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Petrol Pump Management Software v1.0
Auth required
Prerequisites: Access to the application with valid credentials · Ability to upload files in the profile section
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WRITEUP 1 stars
by shubham-s-pandey · poc
https://github.com/shubham-s-pandey/CVE_POC/tree/main/CVE-2024-27744.md

The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-27744, describing XSS vulnerabilities in Petrol Pump Management Software v1.0. The writeups include attack vectors, affected components, and payload examples, demonstrating a clear understanding of the vulnerabilities.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Petrol Pump Management Software v1.0
Auth required
Prerequisites: access to the application · valid credentials
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0409
EPSS Percentile 88.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
mayurik/petrol_pump_management 1.0
Published Mar 01, 2024
Tracked Since Feb 18, 2026