CVE-2024-0286
Phpgurukul
CVE-2024-0286 is a cross-site scripting (XSS) vulnerability in PHPGurukul Hospital Management System 1.0. This flaw allows attackers to inject malicious scripts into the Contact Form (index.php#contact_us) via the Name, Email, or Message fields. Though the CVSS score is 6.1, the SOCRadar Vulnerability Risk Score (SVRS) of 58 indicates a moderate risk. Publicly available exploits mean attackers can readily leverage this vulnerability. Successful exploitation could lead to session hijacking, website defacement, or phishing attacks. Organizations using this system should apply available patches or mitigations promptly to prevent potential compromise and protect user data. This vulnerability is significant because even with a moderate CVSS score, public exploit availability increases the risk of exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.