CVE-2024-27706

Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of crafted SVG file to issues.
Configurations

No configuration.

History

21 Nov 2024, 09:04

Type Values Removed Values Added
References () https://github.com/b-hermes/vulnerability-research/blob/main/CVE-2024-27706/README.md - () https://github.com/b-hermes/vulnerability-research/blob/main/CVE-2024-27706/README.md -

01 Nov 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

04 Apr 2024, 12:48

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Cross Site Scripting en Huly Platform v.0.6.202 permite a los atacantes ejecutar código arbitrario mediante la carga de un archivo SVG manipulado en los problemas.

03 Apr 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-03 21:15

Updated : 2024-11-21 09:04


NVD link : CVE-2024-27706

Mitre link : CVE-2024-27706

CVE.ORG link : CVE-2024-27706


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')