CVE-2024-33306: XSS
Published May 1, 2024
·Updated
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.
Affected Software
2 affected components
Sourcecodester Laboratory Management System
Sourcecodester Laboratory Management System=1.0
Event History
May 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33306?
CVE-2024-33306 is classified as a Cross Site Scripting (XSS) vulnerability that can expose users to malicious scripts.
2
How do I fix CVE-2024-33306?
To fix CVE-2024-33306, sanitize user inputs for the 'First Name' parameter to prevent the execution of malicious scripts.
3
What systems are affected by CVE-2024-33306?
CVE-2024-33306 affects SourceCodester Laboratory Management System version 1.0.
4
How can CVE-2024-33306 be exploited?
CVE-2024-33306 can be exploited by injecting malicious scripts through the 'First Name' parameter during user creation.
5
What are the potential impacts of CVE-2024-33306?
The potential impacts of CVE-2024-33306 include unauthorized access to sensitive user information and session hijacking.