CVE-2024-4645: SourceCodester Prison Management System changepassword.php cross site scripting
A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /Admin/changepassword.php. The manipulation of the argument txtoldpassword/txtnewpassword/txtconfirmpassword leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263489 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4645?
CVE-2024-4645 is classified as problematic and poses a significant security risk.
How do I fix CVE-2024-4645?
To fix CVE-2024-4645, ensure to validate and sanitize input for the password fields in the /Admin/changepassword.php file.
What part of the SourceCodester Prison Management System is affected by CVE-2024-4645?
CVE-2024-4645 affects the password change functionality within the /Admin/changepassword.php file.
What type of attack does CVE-2024-4645 facilitate?
CVE-2024-4645 facilitates cross-site scripting (XSS) attacks due to improper handling of password inputs.
Is SourceCodester Prison Management System version 1.0 vulnerable to CVE-2024-4645?
Yes, version 1.0 of the SourceCodester Prison Management System is vulnerable to CVE-2024-4645.