{"gsd":{"metadata":{"exploitCode":"unknown","remediation":"unknown","reportConfidence":"confirmed","type":"vulnerability"},"osvSchema":{"aliases":["CVE-2024-4293"],"details":"A vulnerability classified as problematic was found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262225 was assigned to this vulnerability.","id":"GSD-2024-4293","modified":"2024-04-28T05:02:06.052534Z","schema_version":"1.4.0"}},"namespaces":{"cve.org":{"CVE_data_meta":{"ASSIGNER":"cna@vuldb.com","ID":"CVE-2024-4293","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Doctor Appointment Management System","version":{"version_data":[{"version_affected":"=","version_value":"1.0"}]}}]},"vendor_name":"PHPGurukul"}]}},"credits":[{"lang":"en","value":"SoSPiro (VulDB User)"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability classified as problematic was found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262225 was assigned to this vulnerability."},{"lang":"deu","value":"In PHPGurukul Doctor Appointment Management System 1.0 wurde eine problematische Schwachstelle entdeckt. Es geht um eine nicht näher bekannte Funktion der Datei appointment-bwdates-reports-details.php. Durch das Manipulieren des Arguments fromdate/todate mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}]},"impact":{"cvss":[{"baseScore":3.5,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},{"baseScore":3.5,"baseSeverity":"LOW","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","version":"3.0"},{"baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","version":"2.0"}]},"problemtype":{"problemtype_data":[{"description":[{"cweId":"CWE-79","lang":"eng","value":"CWE-79 Cross Site Scripting"}]}]},"references":{"reference_data":[{"name":"https://vuldb.com/?id.262225","refsource":"MISC","url":"https://vuldb.com/?id.262225"},{"name":"https://vuldb.com/?ctiid.262225","refsource":"MISC","url":"https://vuldb.com/?ctiid.262225"},{"name":"https://vuldb.com/?submit.323586","refsource":"MISC","url":"https://vuldb.com/?submit.323586"},{"name":"https://github.com/Sospiro014/zday1/blob/main/doctor_appointment_management_system_xss.md","refsource":"MISC","url":"https://github.com/Sospiro014/zday1/blob/main/doctor_appointment_management_system_xss.md"}]}},"nvd.nist.gov":{"cve":{"descriptions":[{"lang":"en","value":"A vulnerability classified as problematic was found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262225 was assigned to this vulnerability."}],"id":"CVE-2024-4293","lastModified":"2024-04-27T22:15:08.110","metrics":{"cvssMetricV2":[{"acInsufInfo":false,"baseSeverity":"MEDIUM","cvssData":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"SINGLE","availabilityImpact":"NONE","baseScore":4.0,"confidentialityImpact":"NONE","integrityImpact":"PARTIAL","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","version":"2.0"},"exploitabilityScore":8.0,"impactScore":2.9,"obtainAllPrivilege":false,"obtainOtherPrivilege":false,"obtainUserPrivilege":false,"source":"cna@vuldb.com","type":"Secondary","userInteractionRequired":false}],"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},"exploitabilityScore":2.1,"impactScore":1.4,"source":"cna@vuldb.com","type":"Secondary"}]},"published":"2024-04-27T22:15:08.110","references":[{"source":"cna@vuldb.com","url":"https://github.com/Sospiro014/zday1/blob/main/doctor_appointment_management_system_xss.md"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?ctiid.262225"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?id.262225"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?submit.323586"}],"sourceIdentifier":"cna@vuldb.com","vulnStatus":"Received","weaknesses":[{"description":[{"lang":"en","value":"CWE-79"}],"source":"cna@vuldb.com","type":"Primary"}]}}}}