CVE-2024-3463
Last modified
CVE-2024-3463 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. The manipulation of the argument karyawan leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259744.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oretnom23 | Laundry Shop Management System | 1.0 |
References
- https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemXSS.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.259744Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.259744Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.312302Third Party Advisory, VDB Entry
- https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemXSS.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.259744Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.259744Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.312302Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3463?
How severe is CVE-2024-3463?
How do I fix CVE-2024-3463?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-34624Out-of-bounds read in applying paragraphs in Samsung Notes p…5.5
- CVE-2024-34625Out-of-bounds read in applying connection point in Samsung N…5.5
- CVE-2024-34626Out-of-bounds read in applying own binary in Samsung Notes p…5.5
- CVE-2024-34627Out-of-bounds read in parsing implemention in Samsung Notes …5.5
- CVE-2024-34628Out-of-bounds read in applying binary with path in Samsung N…5.5
- CVE-2024-34629Out-of-bounds read in applying binary with text common objec…5.5
- CVE-2024-34630Out-of-bounds read in applying own binary with textbox in Sa…5.5
- CVE-2024-34631Out-of-bounds read in applying new binary in Samsung Notes p…5.5
- CVE-2024-34632Out-of-bounds read in uuid parsing in Samsung Notes prior to…3.3
- CVE-2024-34633Out-of-bounds read in parsing object header in Samsung Notes…3.3
- CVE-2024-34634Out-of-bounds read in parsing connected object list in Samsu…3.3
- CVE-2024-34635Out-of-bounds read in parsing textbox object in Samsung Note…3.3
Are you affected by CVE-2024-3463?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
