First published: Mon Dec 09 2024(Updated: )
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lopalopa E-learning Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54936 has a high severity rating due to its impact allowing remote attackers to execute arbitrary scripts.
To fix CVE-2024-54936, validate and sanitize user input for the my_message parameter to prevent script execution.
CVE-2024-54936 affects Kashipara E-learning Management System version 1.0.
Yes, CVE-2024-54936 can be exploited by any remote attacker who sends crafted messages via the my_message parameter.
CVE-2024-54936 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.