Low severity3.5NVD Advisory· Published May 8, 2024· Updated Jun 17, 2026
CVE-2024-4645
CVE-2024-4645
Description
A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /Admin/changepassword.php. The manipulation of the argument txtold_password/txtnew_password/txtconfirm_password leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263489 was assigned to this vulnerability.
Affected products
3- Range: <=1.0
- Range: 1.0
- cpe:2.3:a:fast5:prison_management_system:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/yylmm/CVE/blob/main/Prison%20Management%20System/xss4.mdnvdExploitThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.