CVE-2024-37859: XSS
Published Jul 29, 2024
·Updated
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.
Affected Software
2 affected components
oretnom23 Lost And Found Information System=1.0
Lost and Found Information System Lost and Found Information System
Event History
Jul 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37859?
The severity of CVE-2024-37859 is categorized as high due to its potential for privilege escalation via cross-site scripting.
2
How do I fix CVE-2024-37859?
To fix CVE-2024-37859, sanitize and validate user inputs, specifically the 'page' parameter in php-lfis/admin/index.php.
3
Who is affected by CVE-2024-37859?
Users of Lost and Found Information System version 1.0 are affected by CVE-2024-37859.
4
What type of attack does CVE-2024-37859 enable?
CVE-2024-37859 enables cross-site scripting attacks that can lead to privilege escalation.
5
Can CVE-2024-37859 be exploited remotely?
Yes, CVE-2024-37859 can be exploited remotely by an attacker to escalate privileges.