CVE-2024-3140: SourceCodester Computer Laboratory Management System cross site scripting
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file /classes/Users.php?f=save. The manipulation of the argument middlename leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258915.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3140?
CVE-2024-3140 is classified as a problematic vulnerability that affects the SourceCodester Computer Laboratory Management System 1.0.
How do I fix CVE-2024-3140?
To fix CVE-2024-3140, sanitize and validate user input in the 'middlename' argument of the /classes/Users.php?f=save endpoint.
What type of vulnerability is CVE-2024-3140?
CVE-2024-3140 is a cross-site scripting (XSS) vulnerability.
Which software is affected by CVE-2024-3140?
CVE-2024-3140 affects the SourceCodester Computer Laboratory Management System version 1.0.
Where in the software does CVE-2024-3140 occur?
CVE-2024-3140 occurs in the /classes/Users.php?f=save file within the affected software.