CVE-2024-5373
CVSS 2.0 Score 4.0 of 10 (medium)
Details
Summary
CVE-2024-5373 is a newly disclosed vulnerability affecting the Kashipara College Management System 1.0. The issue arises due to improper handling of user input in the script submit_login.php. Specifically, the argument "usertype" is susceptible to cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by manipulating the "usertype" parameter to inject malicious scripts. The attack can be launched remotely, making it a significant security concern. The exploit for this vulnerability has been made public, increasing the risk of potential attacks. The Vulnerability Database has assigned the identifier VDB-266285 to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.