CVE-2024-33987: Cross-Site Scripting (XSS) vulnerability in Janobe products
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate', 'YearLevel', 'eventdate', 'events', 'Users' and 'YearLevel' parameters in '/report/index.php'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33987?
The severity of CVE-2024-33987 is considered to be high due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-33987?
To fix CVE-2024-33987, upgrade Janobe School Attendance Monitoring System and School Event Management System to a patched version provided by the vendor.
What kind of attack is possible with CVE-2024-33987?
CVE-2024-33987 allows attackers to launch Cross-Site Scripting (XSS) attacks to steal session cookies from users.
Which versions are affected by CVE-2024-33987?
CVE-2024-33987 affects Janobe School Attendance Monitoring System and School Event Management System version 1.0.
What could an attacker achieve through CVE-2024-33987?
An attacker could use CVE-2024-33987 to create a crafted URL that, when visited by a victim, can expose their session cookie.