Skip to content

Latest commit

 

History

History
24 lines (19 loc) · 1.44 KB

CVE-2024-29717 - QR Code Attendance System - Cross-Site-Scripting - 1.md

File metadata and controls

24 lines (19 loc) · 1.44 KB

CVE-2024-29717 - QR Code Attendance System - Cross-Site-Scripting

Description:

QR Code Attendance System is vulnerable to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied data. An attacker could exploit this issue to run arbitrary scripting code in an unsuspecting user's browser in the context of the affected site. This could allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Proof of Concept:

qr code xss 1

qrcode xss 1 2