CVE-2024-7814

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Aug 15, 2024
Updated: Aug 19, 2024
CWE ID 79

Summary

CVE-2024-7814 is a newly disclosed vulnerability affecting the CodeAstro Online Railway Reservation System 1.0. This issue lies within an unidentified function in the file "/admin/admin-add-employee.php" of the "Add Employee Page" component. An attacker can exploit this cross-site scripting (XSS) vulnerability by manipulating the input parameters emp_fname, emp_lname, emp_nat_idno, and emp_addr. Successful exploitation enables the attacker to inject malicious scripts into a victim's browser, potentially leading to data theft or website defacement. The vulnerability can be exploited remotely, and the exploit details have been made public.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share