CVE-2024-6374

CVSS 2.0 Score 4.0 of 10 (medium)

Details

Published Jun 27, 2024
CWE ID 79

Summary

CVE-2024-6374 is a recently disclosed vulnerability affecting lahirudanushka School Management System versions 1.0.0 and 1.0.1. This issue involves the processing of the file /subject.php in the Subject Page component. An attacker can manipulate the arguments Subject Title or Sybillus Details, leading to cross-site scripting (XSS) attacks. These attacks may be initiated remotely, making the vulnerability a significant security concern. The exploit for this vulnerability has been made public, increasing the risk of exploitation. The associated identifier for this vulnerability is VDB-269807.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share