{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-6212","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-06-20T17:26:46.516Z","datePublished":"2024-06-21T00:00:06.024Z","dateUpdated":"2024-08-01T21:33:05.336Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-06-21T00:00:06.024Z"},"title":"SourceCodester Simple Student Attendance System student_form.php get_student cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"CWE-79 Cross Site Scripting"}]}],"affected":[{"vendor":"SourceCodester","product":"Simple Student Attendance System","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the file student_form.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269276."},{"lang":"de","value":"Eine Schwachstelle wurde in SourceCodester Simple Student Attendance System 1.0 gefunden. Sie wurde als problematisch eingestuft. Es geht hierbei um die Funktion get_student der Datei student_form.php. Durch das Manipulieren des Arguments id mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}}],"timeline":[{"time":"2024-06-20T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-06-20T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-06-20T20:25:52.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Guru Raghav Saravanan","type":"finder"},{"lang":"en","value":"R0ck3t (VulDB User)","type":"reporter"},{"lang":"en","value":"R0ck3t (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.269276","name":"VDB-269276 | SourceCodester Simple Student Attendance System student_form.php get_student cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.269276","name":"VDB-269276 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.359229","name":"Submit #359229 | SourceCodester Simple Student Attendance System using PHP and MySQL 1.0 Cross Site Scripting","tags":["third-party-advisory"]},{"url":"https://docs.google.com/document/d/1tl9-EAxUR64Og9zS-nyUx3YtG1V32Monkvq-h39tjpw/edit?usp=sharing","tags":["exploit"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-21T14:12:36.251034Z","id":"CVE-2024-6212","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-21T14:12:49.783Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:33:05.336Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.269276","name":"VDB-269276 | SourceCodester Simple Student Attendance System student_form.php get_student cross site scripting","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.269276","name":"VDB-269276 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.359229","name":"Submit #359229 | SourceCodester Simple Student Attendance System using PHP and MySQL 1.0 Cross Site Scripting","tags":["third-party-advisory","x_transferred"]},{"url":"https://docs.google.com/document/d/1tl9-EAxUR64Og9zS-nyUx3YtG1V32Monkvq-h39tjpw/edit?usp=sharing","tags":["exploit","x_transferred"]}]}]}}