CVE-2024-46300
MEDIUMCVSS 6.1/10EPSS 0.35%
Last modified
CVE-2024-46300 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Angeljudesuarez | Placement Management System | 1.0 |
References
- https://github.com/riya98241/CVE/blob/main/CVE-2024-46300Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-46300?
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
How severe is CVE-2024-46300?
CVE-2024-46300 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2024-46300?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-46278Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via t…8.4
- CVE-2024-46280PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improp…8.8
- CVE-2024-4629A vulnerability was found in Keycloak. This flaw allows atta…6.5
- CVE-2024-46292A buffer overflow in modsecurity v3.0.12 allows attackers to…7.5
- CVE-2024-46293Sourcecodester Online Medicine Ordering System 1.0 is vulner…9.8
- CVE-2024-4630The Starter Templates — Elementor, WordPress & Beaver Builde…6.4
- CVE-2024-46304A NULL pointer dereference in libcoap v4.3.5-rc2 and below a…7.5
- CVE-2024-46307A loop hole in the payment logic of Sparkshop v1.16 allows a…7.5
- CVE-2024-4631Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2024-46310Incorrect Access Control in Cfx.re FXServer v9601 and earlie…9.1
- CVE-2024-46313TP-Link WR941ND V6 has a stack overflow vulnerability in the…8
- CVE-2024-46316DrayTek Vigor3900 v1.5.1.6 was discovered to contain a comma…8
Are you affected by CVE-2024-46300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
