CVE-2024-3443: SourceCodester Prison Management System apply_leave.php cross site scripting
A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/applyleave.php. The manipulation of the argument txtstartdate/txtenddate leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259696.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3443?
CVE-2024-3443 is classified as a problematic vulnerability.
What kind of vulnerability is CVE-2024-3443?
CVE-2024-3443 is a cross-site scripting (XSS) vulnerability.
Which software is affected by CVE-2024-3443?
CVE-2024-3443 affects SourceCodester Prison Management System version 1.0.
How do I fix CVE-2024-3443?
To fix CVE-2024-3443, ensure proper validation and sanitization of the input parameters txtstart_date and txtend_date.
What file is impacted by CVE-2024-3443?
CVE-2024-3443 affects the file /Employee/apply_leave.php.