CVE-2024-13075

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Dec 31, 2024
Updated: Jan 6, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2024-13075 is a recently disclosed vulnerability affecting the PHPGurukul Land Record System 1.0. The issue lies in the manipulation of the argument "Land Property Type" in the file "/admin/add-propertytype.php." This vulnerability results in Cross-Site Scripting (XSS), allowing remote attackers to inject malicious code into the web application. Successful exploitation of this vulnerability can lead to unintended execution of malicious scripts on unsuspecting users' browsers. Organizations utilizing the PHPGurukul Land Record System 1.0 are advised to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Phpgurukul Land Record System

Affected Vendors

  • Phpgurukul