CVE-2024-46081

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.
Configurations

No configuration.

History

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Scriptcase v9.10.023 y versiones anteriores son vulnerables a ataques de Cross-Site Scripting (XSS). Un usuario autenticado puede manipular payloads maliciosos en la lista de tareas pendientes. El usuario asignado activará un XSS almacenado, lo que es particularmente peligroso porque las tareas se asignan a varios usuarios en la plataforma.

01 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

01 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-01 19:15

Updated : 2024-10-04 13:51


NVD link : CVE-2024-46081

Mitre link : CVE-2024-46081

CVE.ORG link : CVE-2024-46081


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')