Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Oct 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Scriptcase
Scriptcase scriptcase |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:scriptcase:scriptcase:*:*:*:*:*:*:*:* | |
Vendors & Products |
Scriptcase
Scriptcase scriptcase |
|
Metrics |
cvssV3_1
|
Tue, 01 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-01T00:00:00
Updated: 2024-10-01T19:36:23.417Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46083
Vulnrichment
Updated: 2024-10-01T19:35:25.307Z
NVD
Status : Awaiting Analysis
Published: 2024-10-01T19:15:09.013
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-46083
Redhat
No data.