CVE-2024-33982: Cross-Site Scripting (XSS) vulnerability in Janobe products
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID' parameter in '/AttendanceMonitoring/student/controller.php'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33982?
CVE-2024-33982 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-33982?
To fix CVE-2024-33982, ensure you update the vulnerable Janobe software to the latest version that addresses this vulnerability.
What systems are affected by CVE-2024-33982?
CVE-2024-33982 affects version 1.0 of the Janobe School Attendance Monitoring System and the School Event Management System.
What is the nature of the vulnerability in CVE-2024-33982?
CVE-2024-33982 is a Cross-Site Scripting (XSS) vulnerability that allows attackers to exploit session cookies through specially crafted URLs.
Can CVE-2024-33982 lead to unauthorized access?
Yes, CVE-2024-33982 can allow attackers to obtain sensitive session information, potentially leading to unauthorized access.