CVE-2024-42918: XSS
itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42918?
CVE-2024-42918 is considered a moderate severity Cross Site Scripting vulnerability.
How do I fix CVE-2024-42918?
To fix CVE-2024-42918, validate and sanitize user input for the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME, and COMPANYCONTACTNO parameters.
Which software is affected by CVE-2024-42918?
CVE-2024-42918 affects version 1.0 of the Adonesevangelista Online Accreditation Management System.
What are the potential impacts of exploiting CVE-2024-42918?
Exploiting CVE-2024-42918 can allow attackers to execute arbitrary code in the context of the user's session.
Is CVE-2024-42918 easy to exploit?
Yes, CVE-2024-42918 can be exploited with a crafted payload targeting specific parameters within the application.