CVE-2024-51108: XSS
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51108?
CVE-2024-51108 is considered a high severity vulnerability due to the potential for arbitrary code execution via stored cross-site scripting.
How do I fix CVE-2024-51108?
To fix CVE-2024-51108, validate and sanitize all user inputs on the /admin/card-bwdates-report.php component to prevent script injection.
Who is affected by CVE-2024-51108?
CVE-2024-51108 affects users of the PHPGURUKUL Medical Card Generation System version 1.0 that utilize the vulnerable component.
What types of attacks can be performed using CVE-2024-51108?
Attackers can exploit CVE-2024-51108 to execute arbitrary web scripts or HTML, leading to session hijacking or data leaks.
Is there a public exploit available for CVE-2024-51108?
There are no known public exploits for CVE-2024-51108 at this time, although its identified vulnerabilities pose significant risks.