CVE-2024-0467: code-projects Employee Profile Management System edit_position_query.php cross site scripting
A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file editpositionquery.php. The manipulation of the argument posname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250572.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0467?
CVE-2024-0467 has been classified as a problematic vulnerability.
How does CVE-2024-0467 affect the Employee Profile Management System?
CVE-2024-0467 affects the unknown function of the file edit_position_query.php, allowing for cross-site scripting due to manipulation of the argument pos_name.
What should I do to fix CVE-2024-0467?
To fix CVE-2024-0467, validate and sanitize input for the pos_name argument in the edit_position_query.php file.
Is CVE-2024-0467 exploitable in the Employee Profile Management System 1.0?
Yes, CVE-2024-0467 is exploitable in version 1.0 of the Employee Profile Management System.
What are the potential impacts of exploiting CVE-2024-0467?
Exploiting CVE-2024-0467 can lead to cross-site scripting, allowing attackers to inject malicious scripts into web pages viewed by users.