First published: Thu Sep 05 2024(Updated: )
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Phpgurukul Job Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8473 has a high severity level due to its potential for Cross-Site Scripting attacks.
To fix CVE-2024-8473, ensure that all user-controlled input is properly sanitized and encoded to prevent XSS vulnerabilities.
CVE-2024-8473 can allow attackers to retrieve session details of authenticated users, compromising user accounts.
CVE-2024-8473 affects PHPGurukul Job Portal version 1.0.
For more information about CVE-2024-8473, refer to security advisories issued related to the vulnerability.