First published: Wed May 08 2024(Updated: )
A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /Admin/changepassword.php. The manipulation of the argument txtold_password/txtnew_password/txtconfirm_password leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263489 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prison Management System | ||
Prison Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4645 is classified as problematic and poses a significant security risk.
To fix CVE-2024-4645, ensure to validate and sanitize input for the password fields in the /Admin/changepassword.php file.
CVE-2024-4645 affects the password change functionality within the /Admin/changepassword.php file.
CVE-2024-4645 facilitates cross-site scripting (XSS) attacks due to improper handling of password inputs.
Yes, version 1.0 of the SourceCodester Prison Management System is vulnerable to CVE-2024-4645.