CVE-2024-9300

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Sep 28, 2024
Updated: Oct 1, 2024
CWE ID 79

Summary

CVE-2024-9300 is a newly disclosed vulnerability affecting the Message Us Form component of SourceCodester Online Railway Reservation System 1.0. The issue lies within the contact_us.php file and allows for cross-site scripting (XSS) attacks. Malicious actors can manipulate the fullname, email, or message arguments to inject malicious scripts, potentially gaining unauthorized access to user sessions or stealing sensitive information. The exploit is publicly known, increasing the risk of attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share