CVE-2024-37856: XSS
Published Jul 29, 2024
·Updated
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.
Affected Software
1 affected component
oretnom23 Lost And Found Information System=1.0
Event History
Jul 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37856?
CVE-2024-37856 is classified as a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2024-37856?
To fix CVE-2024-37856, sanitize and validate user input in the first, last, and middle name fields on the User Profile page.
3
Which versions are affected by CVE-2024-37856?
CVE-2024-37856 affects Lost and Found Information System version 1.0.
4
What type of vulnerability is CVE-2024-37856?
CVE-2024-37856 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-37856 lead to privilege escalation?
Yes, CVE-2024-37856 can allow a remote attacker to escalate privileges.