CVE-2024-27744: XSS
Published Mar 1, 2024
·Updated
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.
Credit
Shubham Pandey
Affected Software
2 affected components
Mayurik Petrol Pump Management=1.0
Unknown Petrol Pump Management Software
Event History
Mar 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Mar 3, 2024
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
via ExploitDB·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-27744?
CVE-2024-27744 is classified as a high severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2024-27744?
To fix CVE-2024-27744, ensure input validation and implement proper encoding on the image parameter in the profile.php component.
3
What type of vulnerability is CVE-2024-27744?
CVE-2024-27744 is a Cross Site Scripting (XSS) vulnerability that can allow an attacker to execute arbitrary code.
4
Which software versions are affected by CVE-2024-27744?
CVE-2024-27744 affects Petrol Pump Management Software version 1.0.
5
What component is vulnerable in CVE-2024-27744?
The vulnerable component in CVE-2024-27744 is the profile.php file associated with the image parameter.