CVE-2024-51430
MEDIUMonline diagnostic lab management system using php 1.0 - Cross-Site Scripting via Test Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-51430. PoCs published by BLACK-SCORP10.
AI-analyzed exploit summary This repository contains a detailed writeup describing a stored XSS vulnerability in the Online Diagnostic Lab Management System v1.0. The vulnerability allows arbitrary JavaScript execution via the 'Test Name' parameter in the diagnostic/add-test.php component.
Description
Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name parameter on the diagnostic/add-test.php component.
Exploits (1)
This repository contains a detailed writeup describing a stored XSS vulnerability in the Online Diagnostic Lab Management System v1.0. The vulnerability allows arbitrary JavaScript execution via the 'Test Name' parameter in the diagnostic/add-test.php component.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N