github.com
https://github.com/kaliankhe/CVE-Aslam-mahi/blob/9ec0572c68bfd3708a7d6e089181024131f4e927/vendors/projectworlds.in/AEGON%20LIFE%20v1.0%20Life%20Insurance%20Management%20System/CVE-2024-36599 CVE-2024-36599
MEDIUM
AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS)
Record summary
CVE-2024-36599 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2024 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBAEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS)ExploitDB exploitby Aslam Anwar MahimkarNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-36599 exploit-db.com
https://www.exploit-db.com/exploits/52042