First published: Tue Aug 06 2024(Updated: )
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/AttendanceMonitoring/report/attendance_print.php'.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe School Attendance Monitoring System | =1.0 | |
Janobe School Event Management System | =1.0 |
There is no reported solution at this time.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33983 is classified as a critical Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2024-33983, update the affected Janobe School Attendance Monitoring System and School Event Management System to a patched version provided by the vendor.
CVE-2024-33983 affects version 1.0 of both the Janobe School Attendance Monitoring System and the Janobe School Event Management System.
CVE-2024-33983 exploits Cross-Site Scripting (XSS) vulnerabilities that allow an attacker to obtain session cookies from victims.
Users and administrators of the Janobe School Attendance Monitoring System and Janobe School Event Management System version 1.0 are impacted by CVE-2024-33983.