github.comexploit
https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System%20-%20xss/College%20Management%20System%20-%20vuln%204.pdf CVE-2024-5370
MEDIUM
Kashipara College Management System submit_enroll_staff.php cross site scripting
Record summary
CVE-2024-5370 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was found in Kashipara College Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file submit_enroll_staff.php. The manipulation of the argument class_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266282 is the identifier assigned to this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 28, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
College Management SystemBrowse Kashipara / College Management System | CVE List | 1.0 | affected |
college_management_systemBrowse college_management_system_project / college_management_systemDefault status: unknown | CVE List | 1.0 | affected |
References
4VDB-266282 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.266282 VDB-266282 | Kashipara College Management System submit_enroll_staff.php cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.266282 Submit #343450 | Kashipara College Management System ≤1.0 XSS injectionThird-party advisory
https://vuldb.com/?submit.343450