Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.
References
Link | Resource |
---|---|
http://insurance.com | Not Applicable |
http://sourcecodester.com | Product |
https://drive.google.com/file/d/1yTIeXAPs3PJcQwj9gxhvs92zTdBwKGVB/view?usp=sharing | Exploit |
https://github.com/sahildari/cve/blob/master/CVE-2024-31064.md | Exploit Third Party Advisory |
http://insurance.com | Not Applicable |
http://sourcecodester.com | Product |
https://drive.google.com/file/d/1yTIeXAPs3PJcQwj9gxhvs92zTdBwKGVB/view?usp=sharing | Exploit |
https://github.com/sahildari/cve/blob/master/CVE-2024-31064.md | Exploit Third Party Advisory |
Configurations
History
03 Apr 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
First Time |
Munyweki
Munyweki insurance Management System |
|
CPE | cpe:2.3:a:munyweki:insurance_management_system:*:*:*:*:*:*:*:* | |
References | () http://insurance.com - Not Applicable | |
References | () http://sourcecodester.com - Product | |
References | () https://drive.google.com/file/d/1yTIeXAPs3PJcQwj9gxhvs92zTdBwKGVB/view?usp=sharing - Exploit | |
References | () https://github.com/sahildari/cve/blob/master/CVE-2024-31064.md - Exploit, Third Party Advisory |
21 Nov 2024, 09:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://insurance.com - | |
References | () http://sourcecodester.com - | |
References | () https://drive.google.com/file/d/1yTIeXAPs3PJcQwj9gxhvs92zTdBwKGVB/view?usp=sharing - | |
References | () https://github.com/sahildari/cve/blob/master/CVE-2024-31064.md - |
30 Oct 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
CWE | CWE-79 | |
Summary |
|
28 Mar 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-28 19:15
Updated : 2025-04-03 15:16
NVD link : CVE-2024-31064
Mitre link : CVE-2024-31064
CVE.ORG link : CVE-2024-31064
JSON object : View
Products Affected
munyweki
- insurance_management_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')