cvedb.io
CVE-2024-51209
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2024-11-20T15:15:08.830 · Last modified 2026-06-17T08:05:30.200

Summary

Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page.

Affected products

phpgurukul — client_management_system

Does this affect you?

Add your gear to cvedb and we'll alert you only when phpgurukul ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.