itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.
References
Link | Resource |
---|---|
https://github.com/khaliquesX/CVE-2024-48415/blob/main/README.md | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
25 Oct 2024, 16:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:loan_management_system_project:loan_management_system:1.0:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.0 |
References | () https://github.com/khaliquesX/CVE-2024-48415/blob/main/README.md - Third Party Advisory | |
First Time |
Loan Management System Project loan Management System
Loan Management System Project |
23 Oct 2024, 16:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
CWE | CWE-79 |
23 Oct 2024, 15:12
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Oct 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-22 22:15
Updated : 2024-10-25 16:55
NVD link : CVE-2024-48415
Mitre link : CVE-2024-48415
CVE.ORG link : CVE-2024-48415
JSON object : View
Products Affected
loan_management_system_project
- loan_management_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')