Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS
History

Tue, 27 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 May 2025 07:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS
Title XSS via WYSIWYG editor
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2025-05-27T07:02:53.607Z

Updated: 2025-05-27T14:55:54.721Z

Reserved: 2024-09-18T11:38:53.583Z

Link: CVE-2024-47090

cve-icon Vulnrichment

Updated: 2025-05-27T14:55:44.487Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-27T07:15:35.067

Modified: 2025-05-28T15:01:30.720

Link: CVE-2024-47090

cve-icon Redhat

No data.