First published: Tue Jan 02 2024(Updated: )
A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument Content with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Engineers Online Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0189 is classified as problematic, indicating a potential for exploitation.
To mitigate CVE-2024-0189, it is recommended to update the RRJ Nueva Ecija Engineer Online Portal to the latest version or patch provided by the vendor.
CVE-2024-0189 affects the Create Message Handler component within the teacher_message.php file.
CVE-2024-0189 involves manipulation of input arguments, potentially leading to unauthorized actions.
CVE-2024-0189 specifically affects version 1.0 of the RRJ Nueva Ecija Engineer Online Portal.