Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-34224. PoCs published by dovankha.
AI-analyzed exploit summary This repository documents a Cross-Site Scripting (XSS) vulnerability in Computer Laboratory Management System using PHP and MySQL 1.0. The vulnerability occurs in the `/php-lms/classes/Users.php?f=save` endpoint via the `firstname`, `middlename`, and `lastname` parameters, allowing arbitrary script injection.
Description
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
Exploits (1)
This repository documents a Cross-Site Scripting (XSS) vulnerability in Computer Laboratory Management System using PHP and MySQL 1.0. The vulnerability occurs in the `/php-lms/classes/Users.php?f=save` endpoint via the `firstname`, `middlename`, and `lastname` parameters, allowing arbitrary script injection.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N