CVE-2024-30987: XSS
Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30987?
CVE-2024-30987 is classified as a cross-site scripting (XSS) vulnerability, which can lead to severe consequences, including arbitrary code execution and data theft.
How do I fix CVE-2024-30987?
To fix CVE-2024-30987, sanitize and validate user input on the fromdate and todate parameters to prevent the execution of arbitrary code.
What systems are affected by CVE-2024-30987?
CVE-2024-30987 affects the Phpgurukul Client Management System using PHP & MySQL version 1.1.
What type of attack does CVE-2024-30987 facilitate?
CVE-2024-30987 facilitates a cross-site scripting attack, allowing attackers to inject malicious scripts into web pages.
What can attackers do with CVE-2024-30987?
Attackers exploiting CVE-2024-30987 can execute arbitrary code and retrieve sensitive information from the system.