Skip to content

dovankha/CVE-2024-34225

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 

Repository files navigation

Computer Laboratory Management System using PHP and MySQL 1.0

Submitter: Kha Do

Vulnerability

Cross Site Scripting

Description

Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.

Affected component

Path URL: php-lms/admin/?page=system_info

Parameters: System name (name), System short name (shortname)

POC

Input payload <script>alert(1337)</script> into System name name and save it. system_name

After saving, the pop-up windows like will appear: system_name_popup

About

CVE-20240-34225 | Cross Site Scripting

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published