github.comexploit
https://github.com/acmglz/bug1_report/blob/main/Record-Management-System-2.md CVE-2024-8137
MEDIUM
SourceCodester Record Management System search_user.php cross site scripting
Record summary
CVE-2024-8137 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file search_user.php. The manipulation of the argument search leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 26, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Record Management SystemBrowse SourceCodester / Record Management SystemDefault status: unknown | CVE List | 1.0 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-8137 VDB-275710 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.275710 VDB-275710 | SourceCodester Record Management System search_user.php cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.275710 Submit #396487 | Sourcecodester Record Management System 1.0 XSSThird-party advisory
https://vuldb.com/?submit.396487 sourcecodester.comproduct
https://www.sourcecodester.com/