CVE-2024-55056

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Dec 17, 2024
CWE ID 79

Summary

CVE-2024-55056 represents a stored cross-site scripting (XSS) vulnerability discovered in the Phpgurukul Online Birth Certificate System 1.0. This issue lies within the /user/certificate-form.php file and specifically affects the full name field. Attackers can take advantage of this vulnerability to inject malicious scripts, which are then permanently stored and executed any time a user views a crafted certificate. Consequently, affected users could be exposed to various attacks, including session hijacking, data theft, or unauthorized actions. Therefore, it is crucial for users to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share