Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Jun 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Savignano
Savignano s-notify |
|
CPEs | cpe:2.3:a:savignano:s-notify:*:*:*:*:*:confluence:*:* | |
Vendors & Products |
Savignano
Savignano s-notify |
Wed, 04 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-04-10T00:00:00
Updated: 2024-12-04T21:04:18.712Z
Reserved: 2024-01-21T00:00:00
Link: CVE-2024-23735

Updated: 2024-08-01T23:13:07.269Z

Status : Analyzed
Published: 2024-04-10T16:15:09.950
Modified: 2025-06-17T17:44:56.820
Link: CVE-2024-23735

No data.