Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view).
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
I-doit
I-doit i-doit |
|
CPEs | cpe:2.3:a:i-doit:i-doit:28:*:*:*:pro:*:*:* | |
Vendors & Products |
I-doit
I-doit i-doit |
Thu, 12 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Sep 2024 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view). | |
Title | Cross-site Scripting vulnerability in Idoit pro | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2024-09-12T11:38:24.912Z
Updated: 2024-09-12T12:54:52.748Z
Reserved: 2024-09-12T09:18:36.000Z
Link: CVE-2024-8750
Vulnrichment
Updated: 2024-09-12T12:54:49.066Z
NVD
Status : Analyzed
Published: 2024-09-12T12:15:54.007
Modified: 2024-09-18T20:38:42.123
Link: CVE-2024-8750
Redhat
No data.