CVE-2024-7368 – SourceCodester Simple Realtime Quiz System ajax.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-7368
A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely. • https://gist.github.com/topsky979/ad93f7046d905cef9277304dd3ac8061 https://vuldb.com/?ctiid.273352 https://vuldb.com/?id.273352 https://vuldb.com/?submit.383516 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-7367 – SourceCodester Simple Realtime Quiz System ajax.php cross-site request forgery
https://notcve.org/view.php?id=CVE-2024-7367
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. • https://vuldb.com/?id.273351 https://vuldb.com/?ctiid.273351 https://vuldb.com/?submit.383515 https://gist.github.com/topsky979/03ae83fd32a94c85f910c8e3a85fa056 • CWE-352: Cross-Site Request Forgery (CSRF) •