CVE-2024-57686
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-57686 is a newly identified Cross Site Scripting (XSS) vulnerability affecting the PHPGurukul Land Record System v1.0, specifically the /landrecordsys/admin/contactus.php file. This issue allows remote attackers to inject and execute malicious scripts in victims' browsers by manipulating the "pagetitle" parameter. Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information or the theft of user credentials, making it a significant threat to system security. Users are encouraged to apply the latest patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Phpgurukul Land Record System