CVE-2024-25202: Code Injection
Published Feb 28, 2024
·Updated
Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.
Affected Software
2 affected components
Phpgurukul User Registration & Login and User Management System
Phpgurukul User Registration \& Login And User Management System=1.0
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25202?
CVE-2024-25202 is classified as a Cross Site Scripting (XSS) vulnerability, which can lead to significant security risks if exploited.
2
How do I fix CVE-2024-25202?
To fix CVE-2024-25202, ensure proper input validation and output encoding in the user input fields, especially in the search bar.
3
What software versions are affected by CVE-2024-25202?
CVE-2024-25202 affects version 1.0 of the Phpgurukul User Registration & Login and User Management System.
4
What types of attacks can be executed via CVE-2024-25202?
Attackers can exploit CVE-2024-25202 to run arbitrary JavaScript code, potentially compromising user sessions and data.
5
Is CVE-2024-25202 easy to exploit?
Yes, CVE-2024-25202 can be easily exploited by entering crafted scripts into the search bar.