A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function of the file /guestbook of the component Guestbook Handler. The manipulation of the argument Content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-270450 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://gitee.com/heyewei/SpringBootCMS/issues/IA9D7F | Exploit Issue Tracking Third Party Advisory |
https://vuldb.com/?ctiid.270450 | Permissions Required VDB Entry |
https://vuldb.com/?id.270450 | Permissions Required Third Party Advisory VDB Entry |
https://gitee.com/heyewei/SpringBootCMS/issues/IA9D7F | Exploit Issue Tracking Third Party Advisory |
https://vuldb.com/?ctiid.270450 | Permissions Required VDB Entry |
https://vuldb.com/?id.270450 | Permissions Required Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 09:49
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 3.5 |
References | () https://gitee.com/heyewei/SpringBootCMS/issues/IA9D7F - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.270450 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.270450 - Permissions Required, Third Party Advisory, VDB Entry |
11 Jul 2024, 14:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitee.com/heyewei/SpringBootCMS/issues/IA9D7F - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.270450 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.270450 - Permissions Required, Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:heyewei:springbootcms:*:*:*:*:*:*:*:* | |
First Time |
Heyewei springbootcms
Heyewei |
|
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 4.8 |
08 Jul 2024, 15:49
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
07 Jul 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-07 23:15
Updated : 2024-11-21 09:49
NVD link : CVE-2024-6539
Mitre link : CVE-2024-6539
CVE.ORG link : CVE-2024-6539
JSON object : View
Products Affected
heyewei
- springbootcms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')