github.comexploit
https://github.com/zw-a11y/VUL/blob/main/Record-Management-System-2.md CVE-2024-7310
MEDIUM
SourceCodester Record Management System sort_user.php cross site scripting
Record summary
CVE-2024-7310 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. The manipulation of the argument sort leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273202 is the identifier assigned to this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Record Management SystemBrowse SourceCodester / Record Management SystemDefault status: unknown | CVE List | 1.0 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-7310 VDB-273202 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.273202 VDB-273202 | SourceCodester Record Management System sort_user.php cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.273202 Submit #382507 | SourceCodester Record Management System 1.0 reflected XSSThird-party advisory
https://vuldb.com/?submit.382507