PoC Index

CVE-2024-34224

HIGH 7.3EPSS 0.9%

Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.

CVSS v3.1
7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
EPSS
0.87% chance of exploitation in the next 30 days, 56th percentile
Published
2024-05-13
Updated
2025-02-13

Proof-of-concept exploits (1)

References

Related