CVE-2024-46238: XSS
Published Oct 21, 2024
·Updated
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
Affected Software
2 affected components
Phpgurukul Hospital Management System
Phpgurukul Hospital Management System=4.0
Event History
Oct 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46238?
CVE-2024-46238 is classified as a high severity vulnerability due to the potential for exploitation through cross-site scripting attacks.
2
How do I fix CVE-2024-46238?
To fix CVE-2024-46238, sanitize and validate the input for the docname parameter in both /admin/add-doctor.php and /admin/edit-doctor.php.
3
What systems are affected by CVE-2024-46238?
CVE-2024-46238 affects PHPGurukul Hospital Management System version 4.0.
4
What type of vulnerabilities are associated with CVE-2024-46238?
CVE-2024-46238 is associated with multiple cross-site scripting (XSS) vulnerabilities.
5
Can CVE-2024-46238 be exploited remotely?
Yes, CVE-2024-46238 can be exploited remotely by attackers through specially crafted requests to the affected endpoints.