CVE-2024-46077: XSS
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and statename parameters in travellers.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46077?
CVE-2024-46077 has been classified as a high severity vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
How do I fix CVE-2024-46077?
To fix CVE-2024-46077, ensure that input validation and output encoding are properly implemented for the affected parameters: val-username, val-email, val-suggestions, val-digits, and state_name.
What software is affected by CVE-2024-46077?
CVE-2024-46077 affects version 1.0 of the itsourcecode Online Tours and Travels Management System.
What are the consequences of exploiting CVE-2024-46077?
Exploiting CVE-2024-46077 can lead to unauthorized access to user data and session hijacking through Cross Site Scripting (XSS).
How can I identify if CVE-2024-46077 is present in my system?
You can identify CVE-2024-46077 by testing the affected parameters for XSS vulnerabilities using crafted payloads.