CVE-2024-33994: Cross-Site Scripting (XSS) vulnerability in Janobe School Event Management System
Published Aug 6, 2024
·Updated
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.
Affected Software
1 affected component
Janobe School Event Management System=1.0
Remediation
Information
There is no reported solution at this time.
Event History
Aug 6, 2024
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33994?
CVE-2024-33994 is classified as a critical Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-33994?
To fix CVE-2024-33994, it is recommended to validate and sanitize all user inputs in the 'view' parameter.
3
Who is affected by CVE-2024-33994?
CVE-2024-33994 affects users of the School Event Management System version 1.0.
4
What type of attack does CVE-2024-33994 enable?
CVE-2024-33994 enables attackers to perform Cross-Site Scripting (XSS) attacks to steal session details.
5
What software is impacted by CVE-2024-33994?
The software impacted by CVE-2024-33994 is the School Event Management System, version 1.0.