CVE-2024-50838
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 120
Summary
CVE-2024-50838 is a stored Cross-Site Scripting (XSS) vulnerability discovered in the /admin/department.php file of the KASHIPARA E-learning Management System Project 1.0. This issue permits remote attackers to inject and execute malicious scripts by exploiting the d and pi parameters, thereby potentially compromising affected systems and stealing sensitive user data or taking unauthorized actions. Users are strongly advised to upgrade to a patched version of the software or implement appropriate security measures to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.