MEDIUM🇵🇱 Wersja polska

CVE-2024-1700

CVSS 4.3v3.1pub. 2024-02-21upd. 2025-02-12

A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument username with the input <script>alert("xss")</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254388. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  • Keerti1924 PHP MySQL User Signup Login System

    APP
    Keerti1924
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2024-2264HIGH7.3same product

A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1....

CVE-2024-2265MEDIUM5.3same product

A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0....

CVE-2024-1701MEDIUM5.3same product

A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affec...

CVE-2024-1702MEDIUM6.3same product

A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected b...

CVE-2024-2271MEDIUM6.3same vendor

A vulnerability classified as critical has been found in keerti1924 Online-Book-Store-Website 1.0. This affect...