CVE-2024-31946

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing malicious JavaScript, executed by the template preview. The following versions fix this: 3.7.42, 3.11.30, 4.3.25, and 4.7.5.
Configurations

No configuration.

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://advisories.stormshield.eu/2024-007 - () https://advisories.stormshield.eu/2024-007 -

30 Oct 2024, 17:35

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.2

16 Jul 2024, 13:43

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Stormshield Network Security (SNS) 3.7.0 a 3.7.41, 3.10.0 a 3.11.29, 4.0 a 4.3.24 y 4.4.0 a 4.7.4. Un usuario que tiene acceso al SNS con acceso de escritura en la página de alertas por correo electrónico tiene la capacidad de crear correos electrónicos de alerta que contienen JavaScript malicioso, ejecutado mediante la vista previa de la plantilla. Las siguientes versiones solucionan este problema: 3.7.42, 3.11.30, 4.3.25 y 4.7.5.

15 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-15 19:15

Updated : 2024-11-21 09:14


NVD link : CVE-2024-31946

Mitre link : CVE-2024-31946

CVE.ORG link : CVE-2024-31946


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')