CVE-2024-40478 Information

Description

A Stored Cross Site Scripting (XSS) vulnerability was found in /admin/afeedback.php\ in Kashipara Online Exam System v1.0 which allows remote attackers to execute arbitrary code via name\ and mail\ parameter fields

Reference

https://www.kashipara.com/project/php/3/online-exam-php-project-source-code-download https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Online%20Exam%20System%20v1.0/Stored%20XSS.pdf

Share on: