CVE-2024-11019

Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*

History

18 Nov 2024, 18:59

Type Values Removed Values Added
First Time Vice
Vice webopac
CPE cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-8216-f7dbf-2.html - () https://www.twcert.org.tw/en/cp-139-8216-f7dbf-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8215-98582-1.html - () https://www.twcert.org.tw/tw/cp-132-8215-98582-1.html - Third Party Advisory

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Webopac de Grand Vice info tiene una vulnerabilidad de Cross-site Scripting reflejado, que permite a atacantes remotos no autenticados ejecutar código JavaScript arbitrario en el navegador del usuario a través de técnicas de phishing.

11 Nov 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-11 07:15

Updated : 2024-11-18 18:59


NVD link : CVE-2024-11019

Mitre link : CVE-2024-11019

CVE.ORG link : CVE-2024-11019


JSON object : View

Products Affected

vice

  • webopac
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')