CVE-2024-30988: XSS
Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30988?
CVE-2024-30988 is classified as a moderate severity vulnerability due to its potential to execute arbitrary code via cross-site scripting.
How do I fix CVE-2024-30988?
To fix CVE-2024-30988, sanitize user input in the search functionality to prevent execution of malicious scripts.
What impact does CVE-2024-30988 have on the phpgurukul Client Management System?
CVE-2024-30988 allows attackers to execute arbitrary code and access sensitive information through the vulnerable search bar.
Is CVE-2024-30988 exploitable in all versions of phpgurukul Client Management System?
CVE-2024-30988 specifically affects the version 1.1 of phpgurukul Client Management System.
Who can be affected by CVE-2024-30988?
Users of phpgurukul Client Management System are at risk if they utilize the search functionality without appropriate input validation.