CVE-2024-57175
MEDIUMPHPGURUKUL Online Birth Certificate System 1.0 - Stored Cross-Site Scripting via Profile Name
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-57175. PoCs published by Ajmal101.
AI-analyzed exploit summary This repository contains a writeup describing a stored XSS vulnerability in PHPGURUKUL Online Birth Certificate System v1.0. The vulnerability allows authenticated users to inject malicious scripts via the profile name field.
Description
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.
Exploits (1)
This repository contains a writeup describing a stored XSS vulnerability in PHPGURUKUL Online Birth Certificate System v1.0. The vulnerability allows authenticated users to inject malicious scripts via the profile name field.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N