CVE-2024-4754

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Cross-site Scripting') en el software Next4Biz CRM y BPM Business Process Manangement (BPM) permite XSS Almacenado. Este problema afecta a Business Process Manangement (BPM): desde 6.6.4.4 antes de 6.6. 4.5.
References () https://www.usom.gov.tr/bildirim/tr-24-0739 - () https://www.usom.gov.tr/bildirim/tr-24-0739 -

24 Jun 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-24 09:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4754

Mitre link : CVE-2024-4754

CVE.ORG link : CVE-2024-4754


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')