CVE-2024-57488
MEDIUMCode-Projects Online Car Rental System 1.0 - Cross-Site Scripting via vehicalorcview Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-57488. PoCs published by aaryan-11-x.
AI-analyzed exploit summary This repository contains detailed technical writeups for CVE-2024-57487 (Authenticated RCE via file upload) and CVE-2024-57488 (Stored XSS in edit-vehicle.php) in the Online Car Rental System. The analysis includes root cause, affected endpoints, and step-by-step reproduction details.
Description
Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.
Exploits (1)
This repository contains detailed technical writeups for CVE-2024-57487 (Authenticated RCE via file upload) and CVE-2024-57488 (Stored XSS in edit-vehicle.php) in the Online Car Rental System. The analysis includes root cause, affected endpoints, and step-by-step reproduction details.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N