github.comexploit
https://github.com/zw-a11y/VUL/blob/main/Record-Management-System-1.md CVE-2024-7309
MEDIUM
SourceCodester Record Management System entry.php cross site scripting
Record summary
CVE-2024-7309 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. The manipulation of the argument school leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273201 was assigned to this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Record Management SystemBrowse SourceCodester / Record Management SystemDefault status: unknown | CVE List | 1.0 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-7309 VDB-273201 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.273201 VDB-273201 | SourceCodester Record Management System entry.php cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.273201 Submit #382506 | SourceCodester Record Management System 1.0 Stored XSSThird-party advisory
https://vuldb.com/?submit.382506