Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-34225. PoCs published by dovankha.
AI-analyzed exploit summary The repository provides a detailed technical description and proof-of-concept for a stored XSS vulnerability in Computer Laboratory Management System 1.0, where the 'name' and 'shortname' parameters in the admin system_info page are vulnerable to script injection. The PoC includes screenshots demonstrating the successful execution of the XSS payload.
Description
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
Exploits (1)
The repository provides a detailed technical description and proof-of-concept for a stored XSS vulnerability in Computer Laboratory Management System 1.0, where the 'name' and 'shortname' parameters in the admin system_info page are vulnerable to script injection. The PoC includes screenshots demonstrating the successful execution of the XSS payload.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N