CVE-2024-57488

MEDIUM

Code-Projects Online Car Rental System 1.0 - Cross-Site Scripting via vehicalorcview Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-57488. PoCs published by aaryan-11-x.

AI-analyzed exploit summary This repository contains detailed technical writeups for CVE-2024-57487 (Authenticated RCE via file upload) and CVE-2024-57488 (Stored XSS in edit-vehicle.php) in the Online Car Rental System. The analysis includes root cause, affected endpoints, and step-by-step reproduction details.

Description

Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

Exploits (1)

github WRITEUP
by aaryan-11-x · poc
https://github.com/aaryan-11-x/CVE-2024-57487-and-CVE-2024-57488

This repository contains detailed technical writeups for CVE-2024-57487 (Authenticated RCE via file upload) and CVE-2024-57488 (Stored XSS in edit-vehicle.php) in the Online Car Rental System. The analysis includes root cause, affected endpoints, and step-by-step reproduction details.

Classification
Writeup 100%
Attack Type
Rce | Xss
Complexity
Trivial
Reliability
Reliable
Target: Online Car Rental System Version 1.0
Auth required
Prerequisites: valid admin credentials
devstral-2 · analyzed May 17, 2026 Full analysis →

Scores

CVSS v3 6.5
EPSS 0.0035
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
code-projects/online_car_rental_system 1.0
Published Jan 13, 2025
Tracked Since Feb 18, 2026