This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending a specially crafted input to the vulnerable parameter to perform reflected Cross Site Scripting (XSS) attacks on the targeted system.
History

Tue, 13 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 10:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending a specially crafted input to the vulnerable parameter to perform reflected Cross Site Scripting (XSS) attacks on the targeted system.
Title Reflected XXS Vulnerability in InstaRISPACS Software
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-08-13T10:18:24.658Z

Updated: 2024-08-13T14:19:41.149Z

Reserved: 2024-03-07T10:09:13.241Z

Link: CVE-2024-2259

cve-icon Vulnrichment

Updated: 2024-08-13T14:19:37.701Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-13T11:15:15.013

Modified: 2024-08-13T12:58:25.437

Link: CVE-2024-2259

cve-icon Redhat

No data.