CVE-2024-35581: XSS
Published May 28, 2024
·Updated
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
Affected Software
1 affected component
Sourcecodester Laboratory Management System
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 28, 2024
CVE Published
via NVD·08:16 PM
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Aug 2, 2024
Data Sourced
via MITRE·03:21 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35581?
CVE-2024-35581 is considered a high severity vulnerability due to its potential to allow attackers to execute arbitrary scripts.
2
How do I fix CVE-2024-35581?
To fix CVE-2024-35581, validate and sanitize the Borrower Name input field to prevent script injection.
3
What systems are affected by CVE-2024-35581?
CVE-2024-35581 affects Sourcecodester Laboratory Management System version 1.0.
4
What type of vulnerability is CVE-2024-35581?
CVE-2024-35581 is a cross-site scripting (XSS) vulnerability.
5
How can CVE-2024-35581 impact users?
CVE-2024-35581 can impact users by allowing attackers to execute arbitrary web scripts, potentially leading to data theft or session hijacking.