CVE-2024-51328: XSS
Published Nov 4, 2024
·Updated
Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.
Affected Software
2 affected components
Projectworlds Travel management System=1.0
projectworld Travel Management System
Event History
Nov 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51328?
CVE-2024-51328 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-51328?
To fix CVE-2024-51328, sanitize and validate the 't2' parameter in addcategory.php input to prevent code injection.
3
Who is affected by CVE-2024-51328?
CVE-2024-51328 affects users of projectworld's Travel Management System version 1.0.
4
What type of attack is associated with CVE-2024-51328?
CVE-2024-51328 is associated with Cross-Site Scripting (XSS) attacks that can be exploited by remote attackers.
5
What does CVE-2024-51328 allow attackers to do?
CVE-2024-51328 allows remote attackers to inject arbitrary code through the 't2' parameter in the Travel Management System.