Vulnerability Description
A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an unknown part of the file /admin/edit-brand.php. The manipulation of the argument Brand Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions the parameter "phone_number" to be affected. But this might be a mistake because the textbox field label is "Brand Name".
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Vehicle Record System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/jadu101/CVE/blob/main/phpgurukul_vehicle_record_system_edit_bExploitThird Party Advisory
- https://phpgurukul.com/Product
- https://vuldb.com/?ctiid.281955Permissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.281955Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.431623Third Party AdvisoryVDB Entry
FAQ
What is CVE-2024-10414?
CVE-2024-10414 is a vulnerability with a CVSS score of 2.4 (LOW). A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an unknown part of the file /admin/edit-brand.php. The manipulation of the argumen...
How severe is CVE-2024-10414?
CVE-2024-10414 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10414?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Vehicle Record System.