code-projects Hostel Management System 1.0 /admin/registration.php fname/mname/lname Skriptovanje preko sajta

Identifikovana je ranjivost klasifikovana kao Problematiиno u code-projects Hostel Management System 1.0. Obuhvaćeno je nepoznata funkcija u fajlu /admin/registration.php. Promena parametra fname/mname/lname uzrokuje Skriptovanje preko sajta. Korišćenjem CWE za opis problema dolazi se do CWE-79. Objava slabosti je izvršena 12/28/2024. Ova ranjivost je poznata pod oznakom CVE-2024-13012. Napad je moguće izvršiti sa udaljene lokacije. Napad zahteva pristup lokalnoj mreži. Tehnički podaci su dostupni. Штавише, експлоит је доступан. U ovom trenutku, trenutna cena za eksploataciju može iznositi oko USD $0-$5k. Prema MITRE ATT&CK projektu, tehnika napada je T1059.007. Definisano je kao dokaz-of-koncept. Kao 0-day, očekivana cena na crnom tržištu bila je oko $0-$5k. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

4 Promene · 97 Tačke podataka

PoljeKreirali
12/28/2024 17:21
Ažurira 1/3
12/29/2024 13:44
Ažurira 2/3
02/16/2025 14:33
Ažurira 3/3
02/19/2025 03:12
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss4_vuldb_eXXXX
cvss2_vuldb_basescore4.04.04.04.0
cvss2_vuldb_tempscore3.83.83.83.8
cvss3_vuldb_basescore3.53.53.53.5
cvss3_vuldb_tempscore3.43.43.43.4
cvss3_meta_basescore3.53.53.54.4
cvss3_meta_tempscore3.43.43.44.3
cvss4_vuldb_bscore5.35.35.15.1
cvss4_vuldb_btscore5.35.35.15.1
advisory_date1735340400 (12/28/2024)1735340400 (12/28/2024)1735340400 (12/28/2024)1735340400 (12/28/2024)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
software_vendorcode-projectscode-projectscode-projectscode-projects
software_nameHostel Management SystemHostel Management SystemHostel Management SystemHostel Management System
software_version1.01.01.01.0
software_file/admin/registration.php/admin/registration.php/admin/registration.php/admin/registration.php
software_argumentfname/mname/lnamefname/mname/lnamefname/mname/lnamefname/mname/lname
vulnerability_cweCWE-79 (Skriptovanje preko sajta)CWE-79 (Skriptovanje preko sajta)CWE-79 (Skriptovanje preko sajta)CWE-79 (Skriptovanje preko sajta)
vulnerability_risk1111
cvss3_vuldb_avNNNN
cvss3_vuldb_acLLLL
cvss3_vuldb_uiRRRR
cvss3_vuldb_sUUUU
cvss3_vuldb_cNNNN
cvss3_vuldb_iLLLL
cvss3_vuldb_aNNNN
cvss3_vuldb_rcRRRR
exploit_availability1111
source_cveCVE-2024-13012CVE-2024-13012CVE-2024-13012CVE-2024-13012
cna_responsibleVulDBVulDBVulDBVulDB
software_typeProject Management SoftwareProject Management SoftwareProject Management SoftwareProject Management Software
cvss2_vuldb_avNNNN
cvss2_vuldb_acLLLL
cvss2_vuldb_ciNNNN
cvss2_vuldb_iiPPPP
cvss2_vuldb_aiNNNN
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avNNNN
cvss4_vuldb_acLLLL
cvss4_vuldb_vcNNNN
cvss4_vuldb_viLLLL
cvss4_vuldb_vaNNNN
cvss2_vuldb_auSSSS
cvss2_vuldb_eNDNDNDND
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_prLLLL
cvss3_vuldb_eXXXX
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_prLLLL
cvss4_vuldb_uiNNPP
cve_nvd_summaryA vulnerability, which was classified as problematic, has been found in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /admin/registration.php. The manipulation of the argument fname/mname/lname leads to cross site scripting. The attack may be initiated remotely.A vulnerability, which was classified as problematic, has been found in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /admin/registration.php. The manipulation of the argument fname/mname/lname leads to cross site scripting. The attack may be initiated remotely.A vulnerability, which was classified as problematic, has been found in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /admin/registration.php. The manipulation of the argument fname/mname/lname leads to cross site scripting. The attack may be initiated remotely.
cvss4_cna_avNNN
cvss4_cna_acLLL
cvss4_cna_atNNN
cvss4_cna_prLLL
cvss4_cna_uiNNN
cvss4_cna_vcNNN
cvss4_cna_viLLL
cvss4_cna_vaNNN
cvss4_cna_scNNN
cvss4_cna_siNNN
cvss4_cna_saNNN
cvss4_cna_bscore5.35.35.3
cvss3_cna_avNNN
cvss3_cna_acLLL
cvss3_cna_prLLL
cvss3_cna_uiRRR
cvss3_cna_sUUU
cvss3_cna_cNNN
cvss3_cna_iLLL
cvss3_cna_aNNN
cvss3_cna_basescore3.53.53.5
cvss2_cna_avNNN
cvss2_cna_acLLL
cvss2_cna_auSSS
cvss2_cna_ciNNN
cvss2_cna_iiPPP
cvss2_cna_aiNNN
cvss2_cna_basescore444
cve_nvd_summaryesSe ha encontrado una vulnerabilidad clasificada como problemática en code-projects Hostel Management System 1.0. Este problema afecta a algunos procesos desconocidos del archivo /admin/registration.php. La manipulación del argumento fname/mname/lname provoca ataques de cross site scripting. El ataque puede iniciarse de forma remota.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prN
cvss3_nvd_uiR
cvss3_nvd_sC
cvss3_nvd_cL
cvss3_nvd_iL
cvss3_nvd_aN
cvss3_nvd_basescore6.1

Do you know our Splunk app?

Download it now for free!