Threats Tagged 'cve-2024-46335'
View all threats tagged with 'cve-2024-46335'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-46335'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2024-46335 is a medium severity Cross Site Scripting (XSS) vulnerability found in PHPGurukul Complaint Management System 2.0, specifically in the fromdate and todate parameters of the between-date-userreport.php script. The flaw allows an authenticated user to inject malicious scripts due to insufficient input sanitization, potentially leading to limited confidentiality and integrity impacts. Exploitation requires user interaction and privileges, and no known exploits are currently reported in the wild. The vulnerability does not affect system availability. European organizations using this complaint management system may face risks of session hijacking or data manipulation if exploited. Mitigation involves implementing strict input validation and output encoding on the affected parameters and restricting access to trusted users. Countries with higher adoption of PHPGurukul products or similar PHP-based complaint systems, such as the UK, Germany, and France, are more likely to be impacted. Given the medium CVSS score of 4. Join the discussion | CVE Database V5 | 11/17/2025, 00:00:00 UTC Added: 11/17/2025, 18:41:51 UTC |
Showing 1 to 1 of 1 result