CVE-2024-51107: XSS
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.
Affected Software
Event History
Frequently Asked Questions
What are the impacts of CVE-2024-51107?
CVE-2024-51107 allows attackers to execute arbitrary web scripts or HTML through multiple stored cross-site scripting vulnerabilities.
How do I fix CVE-2024-51107?
To mitigate CVE-2024-51107, sanitize and validate all user inputs on the /mcgs/admin/contactus.php component.
Who is affected by CVE-2024-51107?
CVE-2024-51107 affects the PHPGURUKUL Medical Card Generation System version 1.0.
What input fields are vulnerable in CVE-2024-51107?
The pagetitle, pagedes, and email fields are vulnerable in CVE-2024-51107.
Is CVE-2024-51107 a critical vulnerability?
CVE-2024-51107 is considered a serious vulnerability due to its potential for storing and executing malicious web scripts.