CVE-2024-30986: XSS
Published Apr 17, 2024
·Updated
Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter.
Affected Software
1 affected component
Phpgurukul Client Management System
Event History
Apr 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30986?
CVE-2024-30986 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2024-30986?
To fix CVE-2024-30986, sanitize and validate the user input for the 'price' and 'sname' parameters before processing.
3
What impact does CVE-2024-30986 have on my application?
CVE-2024-30986 allows attackers to execute arbitrary code, potentially compromising the integrity and confidentiality of the application.
4
Is CVE-2024-30986 exploitable without user interaction?
Yes, CVE-2024-30986 can be exploited without user interaction if an attacker can insert malicious scripts into the application.
5
Which versions of the Phpgurukul Client Management System are affected by CVE-2024-30986?
CVE-2024-30986 affects the Phpgurukul Client Management System version 1.1.