Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.sourcecodester.com/php/17375/best-courier-management-system-project-php.html | product |
https://github.com/jubilianite/CVEs/blob/main/CVE-2024-40576.md | third party advisory exploit |
https://github.com/jubilianite/CVEs/security/advisories/GHSA-674x-j9wj-qvpp | third party advisory exploit |