CVE-2024-13077

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Dec 31, 2024
Updated: Jan 6, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2024-13077 is a recently disclosed vulnerability affecting the PHPGurukul Land Record System 1.0. This issue lies within an unidentified function in the /admin/add-property.php file. The vulnerability is classified as problematic due to the potential for cross-site scripting (XSS) attacks. An attacker can manipulate the Land Subtype argument, enabling them to inject malicious code that can be executed in the context of the affected website. The attack can be launched remotely, increasing the risk for potential exploitation. Public disclosure of the exploit heightens the urgency for affected organizations to apply patches or mitigations to protect against this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Phpgurukul Land Record System

Affected Vendors

  • Phpgurukul