CVE-2024-55100: XSS
Published Dec 16, 2024
·Updated
A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter.
Affected Software
2 affected components
Phpgurukul Online Nurse Hiring System=1.0
Online Nurse Hiring System Online Nurse Hiring System
Event History
Dec 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-55100?
CVE-2024-55100 is considered a high severity vulnerability due to its potential for executing arbitrary scripts.
2
How do I fix CVE-2024-55100?
To fix CVE-2024-55100, validate and sanitize input for the fullname parameter in the /admin/profile.php component.
3
Who is affected by CVE-2024-55100?
The vulnerability CVE-2024-55100 affects users of Online Nurse Hiring System version 1.0.
4
What type of vulnerability is CVE-2024-55100?
CVE-2024-55100 is a stored cross-site scripting (XSS) vulnerability.
5
What is the attack vector for CVE-2024-55100?
The attack vector for CVE-2024-55100 involves injecting a crafted payload into the fullname parameter to execute scripts.