CVE-2024-7815
CodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin-update-employee.php of the component Update Employee Page. The manipulation of the argument emp_fname /emp_lname /emp_nat_idno/emp_addr leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
In CodeAstro Online Railway Reservation System 1.0 wurde eine Schwachstelle gefunden. Sie wurde als problematisch eingestuft. Das betrifft eine unbekannte Funktionalität der Datei /admin/admin-update-employee.php der Komponente Update Employee Page. Durch Manipulieren des Arguments emp_fname /emp_lname /emp_nat_idno/emp_addr mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-08-14 CVE Reserved
- 2024-08-15 CVE Published
- 2024-08-15 CVE Updated
- 2024-08-15 First Exploit
- 2024-08-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.274711 | Technical Description | |
https://vuldb.com/?submit.391376 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/CYB84/CVE_Writeup/blob/main/Online%20Railway%20Reservation%20System/Stored%20XSS.md | 2024-08-15 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
CodeAstro Search vendor "CodeAstro" | Online Railway Reservation System Search vendor "CodeAstro" for product "Online Railway Reservation System" | 1.0 Search vendor "CodeAstro" for product "Online Railway Reservation System" and version "1.0" | en |
Affected
|