A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 94bf9ab7ad0ccb7fbdc02f172f37f0e2ea08d48f. It is recommended to apply a patch to fix this issue.
History

Fri, 20 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Jeanmarc77
Jeanmarc77 123solar
CPEs cpe:2.3:a:jeanmarc77:123solar:1.8.4.5:*:*:*:*:*:*:*
Vendors & Products Jeanmarc77
Jeanmarc77 123solar
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 22:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 94bf9ab7ad0ccb7fbdc02f172f37f0e2ea08d48f. It is recommended to apply a patch to fix this issue.
Title jeanmarc77 123solar detailed.php cross site scripting
Weaknesses CWE-79
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-09-19T22:31:07.360Z

Updated: 2024-09-20T13:39:09.819Z

Reserved: 2024-09-19T15:55:15.446Z

Link: CVE-2024-9007

cve-icon Vulnrichment

Updated: 2024-09-20T13:39:03.894Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-19T23:15:12.830

Modified: 2024-09-25T18:40:31.320

Link: CVE-2024-9007

cve-icon Redhat

No data.