CVE-2024-53635

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Nov 27, 2024
CWE ID 79

Summary

CVE-2024-53635 is a newly identified Reflected Cross Site Scripting (XSS) vulnerability. This issue affects the patient-search-report.php file in the PHPGurukul COVID 19 Testing Management System v1.0. An attacker can exploit this vulnerability by manipulating the searchdata POST request parameter, allowing them to execute arbitrary code remotely. Successful exploitation could lead to unintended execution of malicious scripts in the context of the affected system. This vulnerability poses a significant risk and requires immediate attention from system administrators and users to apply the necessary security patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share