ZeroHour

CVE-2024-42762

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p37
Published
()
Modified
Description

A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the Name, Phone, and Email parameter fields.

Vendors
kjayvik
Products
bus ticket reservation system
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.