CVE-2024-51031

MEDIUM

Oretnom23 Cab Management System - XSS

Title source: rule
STIX 2.1

Description

A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.

Exploits (1)

nomisec WRITEUP
by vighneshnair7 · poc
https://github.com/vighneshnair7/CVE-2024-51031

Scores

CVSS v3 5.4
EPSS 0.0101
EPSS Percentile 77.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
oretnom23/cab_management_system 1.0
Published Nov 08, 2024
Tracked Since Feb 18, 2026