Gladinet · Gladinet Centrestack · CVE-2024-37783
**Name of the Vulnerable Software and Affected Versions**
Gladinet CentreStack version 13.12.9934.54690
**Description**
A reflected cross-site scripting (XSS) issue allows attackers to inject malicious JavaScript into a victim's web browser via the `sessionId` parameter at the "/portal/ForgotPassword.aspx" API endpoint. This can lead to unauthorized access to sensitive information.
**Recommendations**
For Gladinet CentreStack version 13.12.9934.54690, consider restricting access to the "/portal/ForgotPassword.aspx" endpoint until a patch is available, and avoid using the `sessionId` parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.