Metrics
Affected Vendors & Products
Mon, 09 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Talentera
Talentera talentera |
|
CPEs | cpe:2.3:a:talentera:talentera:*:*:*:*:*:*:*:* | |
Vendors & Products |
Talentera
Talentera talentera |
|
Metrics |
ssvc
|
Sun, 08 Dec 2024 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation of the argument redirect_url leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The provided PoC only works in Mozilla Firefox. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Talentera byt_cv_manager cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-08T23:31:05.563Z
Updated: 2024-12-09T15:46:53.793Z
Reserved: 2024-12-08T07:58:36.405Z
Link: CVE-2024-12346
Updated: 2024-12-09T15:46:44.781Z
Status : Received
Published: 2024-12-09T00:15:04.207
Modified: 2024-12-09T00:15:04.207
Link: CVE-2024-12346
No data.