Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack.
Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Dec 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache answer |
|
CPEs | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache answer |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: apache
Published: 2024-02-22T09:48:20.873Z
Updated: 2025-03-28T19:39:55.576Z
Reserved: 2024-01-16T02:49:36.161Z
Link: CVE-2024-23349

Updated: 2024-08-01T22:59:32.284Z

Status : Modified
Published: 2024-02-22T10:15:08.427
Modified: 2025-03-28T20:15:21.263
Link: CVE-2024-23349

No data.