CVE-2024-40481: XSS
A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute arbitrary code via the Contact Us page "message" parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40481?
The severity of CVE-2024-40481 is considered high due to its potential for remote code execution through stored XSS.
How do I fix CVE-2024-40481?
To fix CVE-2024-40481, you should sanitize and validate all user inputs in the Contact Us page's message parameter.
Who is affected by CVE-2024-40481?
CVE-2024-40481 affects users of PHPGurukul Old Age Home Management System version 1.0.
What types of attacks can happen due to CVE-2024-40481?
Due to CVE-2024-40481, attackers can exploit the stored XSS vulnerability to execute arbitrary scripts in the context of a victim's browser.
Is CVE-2024-40481 a zero-day vulnerability?
CVE-2024-40481 is not classified as a zero-day vulnerability as it has been publicly disclosed.