CVE-2024-48246 Details
Description
Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.
A stored cross-site scripting vulnerability has been identified in Vehicle Management System version 1.0. The issue resides in the 'Name' parameter of the 'booking.php' file within the vehicle management module. This vulnerability allows attackers to inject malicious scripts that are executed when an administrator views the booking list on 'bookinglist.php'. Such exploitation could lead to session hijacking or unauthorized access to administrative accounts.
Users are advised to sanitize and encode user input for all parameters, particularly the 'Name' parameter. Implementing a Content Security Policy (CSP) to restrict script execution is also recommended. If a patched version is available, users should update to it.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ShadowByte1/CVE-2024-48246 | [email protected] | ExploitMitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| janobe vehicle management system | 1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 31, 2025 | Modified Analysis | [email protected] |
| May 21, 2025 | Initial Analysis | [email protected] |
| Mar 6, 2025 | CVE Modified | CISA-ADP |
| Mar 5, 2025 | New CVE Received | [email protected] |