OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.
History

Wed, 22 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 21:00:00 +0000

Type Values Removed Values Added
Description OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-21T00:00:00.000Z

Updated: 2025-01-22T21:53:34.918Z

Reserved: 2024-10-08T00:00:00.000Z

Link: CVE-2024-48392

cve-icon Vulnrichment

Updated: 2025-01-22T21:53:28.669Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-21T21:15:10.837

Modified: 2025-01-22T22:15:09.283

Link: CVE-2024-48392

cve-icon Redhat

No data.