Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack.
Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Dec 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache answer |
|
CPEs | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache answer |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-02-22T09:48:20.873Z
Updated: 2024-08-01T22:59:32.284Z
Reserved: 2024-01-16T02:49:36.161Z
Link: CVE-2024-23349
Vulnrichment
Updated: 2024-08-01T22:59:32.284Z
NVD
Status : Analyzed
Published: 2024-02-22T10:15:08.427
Modified: 2024-12-11T14:22:19.183
Link: CVE-2024-23349
Redhat
No data.