CVE-2024-42763
CVE-2024-42763: Reflected Cross-Site Scripting (XSS) vulnerability in Kashipara Bus Ticket Reservation System v1.0. Attackers can exploit the "/schedule.php" page using the "bookingdate" parameter to inject and execute malicious code in a user's browser. This vulnerability arises because the application fails to properly sanitize user-supplied input.
With an SVRS of 30, while not critical, this vulnerability still warrants attention. Successful exploitation of CVE-2024-42763 could lead to session hijacking, defacement of the web page, or redirection of users to malicious sites. Addressing this XSS issue in the Kashipara Bus Ticket Reservation System v1.0 is crucial to protect user data and maintain the system's integrity.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.