CVE-2024-2727

HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
Configurations

No configuration.

History

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-cigesv2-system - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-cigesv2-system -
Summary
  • (es) Vulnerabilidad de inyección de HTML que afecta al sistema CIGESv2, que permite a un atacante inyectar código arbitrario y modificar elementos del sitio web y del mensaje de confirmación del correo electrónico.

22 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-22 14:15

Updated : 2024-11-21 09:10


NVD link : CVE-2024-2727

Mitre link : CVE-2024-2727

CVE.ORG link : CVE-2024-2727


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')