Skip to content

Cross Site Scripting (XSS) in Best House Rental Management System v1.0

Moderate
jubilianite published GHSA-674x-j9wj-qvpp Jul 29, 2024

Package

index.php (Best House Rental Management)

Affected versions

1.0

Patched versions

None

Description

CVE-2024-40576

Cross Site Scripting (XSS) in Best House Rental Management System v1.0

Description

Cross Site Scripting Vulnerability in Best House Rental Management System v1.0 allows an attacker to execute arbitrary code via the "House No" and "Description" fields in the houses page at index.php

Proof of Concept (PoC)

image
image
image

Payload(s)

<script>alert(1);</script>
<script>alert(document.cookie);</script>

Impact / Implications

Attackers can inject HTML or JavaScript codes that reflect at anyone who visits the page.

Severity

Moderate

CVE ID

CVE-2024-40576

Weaknesses

No CWEs

Credits