CVE-2024-1022
Last modified
CVE-2024-1022 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6. This affects an unknown part of the file /add_classes.php of the component Add Class Page. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6. This affects an unknown part of the file /add_classes.php of the component Add Class Page. The manipulation of the argument Class Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252291.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Farahkharrat | Simple Student Result Management System | 5.6 |
References
- https://drive.google.com/file/d/1lPZ1yL9UlU-uB03xz17q4OR9338X_1am/view?usp=sharingExploit, Third Party Advisory
- https://vuldb.com/?ctiid.252291Permissions Required, Third Party Advisory
- https://vuldb.com/?id.252291Third Party Advisory
- https://drive.google.com/file/d/1lPZ1yL9UlU-uB03xz17q4OR9338X_1am/view?usp=sharingExploit, Third Party Advisory
- https://vuldb.com/?ctiid.252291Permissions Required, Third Party Advisory
- https://vuldb.com/?id.252291Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-1022?
How severe is CVE-2024-1022?
How do I fix CVE-2024-1022?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10214Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrec…3.5
- CVE-2024-10215The WPBookit plugin for WordPress is vulnerable to Arbitrary…9.8
- CVE-2024-10216The WP User Manager – User Profile Builder & Membership plug…4.3
- CVE-2024-10217XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utili…9.2
- CVE-2024-10218XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utili…9.2
- CVE-2024-10219An issue has been discovered in GitLab CE/EE affecting all v…6.5
- CVE-2024-10220The Kubernetes kubelet component allows arbitrary command ex…8.1
- CVE-2024-10222The SVG Support plugin for WordPress is vulnerable to Stored…5.4
- CVE-2024-10223The WP Team – WordPress Team Member Plugin plugin for WordPr…6.4
- CVE-2024-10224Qualys discovered that if unsanitized input was used with th…7.8
- CVE-2024-10225A vulnerability in haotian-liu/llava v1.2.0 allows an attack…7.5
- CVE-2024-10226The Arconix Shortcodes plugin for WordPress is vulnerable to…5.4
Are you affected by CVE-2024-1022?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
