A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/campsdetails.php. The manipulation of the argument hospital/address/city/contact leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9805. The attack may be initiated remotely. Furthermore, there is an exploit available.
The initial researcher advisory only mentions the parameter "hospital".
A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the component Room Page. The manipulation of the argument Name leads to cross site scripting.
This vulnerability was named CVE-2024-9806. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
The project maintainer was contacted early about the disclosure. He responded very quickly, friendly, and professional.
A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component Session Page. The manipulation of the argument Name leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9807. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
The project maintainer was contacted early about the disclosure. He responded very quickly, friendly, and professional.
A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file sort2_user.php. The manipulation of the argument qualification leads to cross site scripting.
This vulnerability is handled as CVE-2024-9810. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in Adobe Commerce up to 2.4.7-p2/2.4.6-p7/2.4.5-p9/2.4.4-p10 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to time-of-check time-of-use.
This vulnerability was named CVE-2024-45120. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.