CVE-2024-40478 Information
Aug 14, 2024
cve
Description
A Stored Cross Site Scripting (XSS) vulnerability was found in /admin/afeedback.php\ in Kashipara Online Exam System v1.0 which allows remote attackers to execute arbitrary code via name\ and mail\ parameter fields
Reference
https://www.kashipara.com/project/php/3/online-exam-php-project-source-code-download https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Online%20Exam%20System%20v1.0/Stored%20XSS.pdf
Share on: