Feed/CVE-2024-3525
CVE-2024-3525LOWCVSS 3.5

CVE-2024-3525

Published Apr 9, 2024·Updated Jun 17, 2026

NVD Description

A vulnerability, which was classified as problematic, was found in Campcodes Online Event Management System 1.0. Affected is an unknown function of the file /views/index.php. The manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259896.

Public Exploits & PoCs7 found

[POC] CVE-2024-35250 — CVE-2024-35250

PoC for the Untrusted Pointer Dereference in the ks.sys driver

2

[POC] CVE-2024-35250 — CVE-2024-35250-BOF

Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)

1

[POC] CVE-2024-35250 — HVCIPwned

CVE-2024-35250 demonstrates that HVCI is not a defense against data-only kernel exploits. As long as a driver bug provides an arbitrary R/W primitive, token swap remains a universal SYSTEM elevation technique — no code execution required.

1

[POC] CVE-2024-35250 — CVE-2024-35250

PoC for the Untrusted Pointer Dereference in the ks.sys driver

[POC] CVE-2024-35250 — CVE-2024-35250-BOF

Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)

[POC] CVE-2024-35250 — GiveMeKernel

CVE-2024-35250 PoC - Optimized & Condensed Form of Varwara's PoC

[POC] CVE-2024-35250 — CVE-2024-35250-BOF

CVE-2024-35250 的 Beacon Object File (BOF) 实现。

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free