CVE-2024-44728: XSS
Published Sep 5, 2024
·Updated
Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.
Affected Software
1 affected component
Angeljudesuarez Event Management System=1.0
Event History
Sep 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-44728?
CVE-2024-44728 has a high severity rating due to its potential for allowing Stored Cross-Site Scripting attacks.
2
How do I fix CVE-2024-44728?
To fix CVE-2024-44728, validate and sanitize all user inputs from the Full Name, Address, Email, and contact# parameters.
3
Who is affected by CVE-2024-44728?
Any user of the Sourcecodehero Event Management System version 1.0 is affected by CVE-2024-44728.
4
What type of vulnerability is CVE-2024-44728?
CVE-2024-44728 is classified as a Stored Cross-Site Scripting vulnerability.
5
Where does CVE-2024-44728 occur in the application?
CVE-2024-44728 occurs in the /clientdetails/admin/regester.php file of the Sourcecodehero Event Management System.