CVE-2024-34469
HIGHRukovoditel < 3.5.3 - Cross-Site Scripting via User Photo Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-34469. PoCs published by Toxich4.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-34469, an XSS vulnerability in Rukovoditel up to version 3.5.3. It includes HTTP request examples demonstrating how the vulnerability can be exploited via the 'user_photo' parameter in both user account updates and registration forms.
Description
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2024-34469, an XSS vulnerability in Rukovoditel up to version 3.5.3. It includes HTTP request examples demonstrating how the vulnerability can be exploited via the 'user_photo' parameter in both user account updates and registration forms.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L