CVE-2024-53481: XSS
Published Dec 10, 2024
·Updated
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
Affected Software
2 affected components
Phpgurukul Beauty Parlour Management System
Phpgurukul Beauty Parlour Management System=1.1
Event History
Dec 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53481?
CVE-2024-53481 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-53481?
To fix CVE-2024-53481, ensure that proper input validation and sanitization are implemented for the 'Firstname' and 'Last name' parameters.
3
Who is affected by CVE-2024-53481?
CVE-2024-53481 affects users of PHPGurukul Beauty Parlour Management System version 1.1.
4
What type of vulnerability is CVE-2024-53481?
CVE-2024-53481 is a Cross Site Scripting (XSS) vulnerability.
5
Can CVE-2024-53481 allow attackers to execute code?
Yes, CVE-2024-53481 allows remote attackers to execute arbitrary code by injecting HTML into specified parameters.