Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stehled1

#43746of 53,630
6.1Total CVSS
Vulnerabilities · 1
PT-2024-20894
6.1
2024-02-26
Unknown · Itflow.Org · CVE-2024-25344
**Name of the Vulnerable Software and Affected Versions** ITFlow.org versions prior to commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 **Description** A Cross Site Scripting issue allows a remote attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings defaults.php, settings integrations.php, settings invoice.php, settings localization.php, settings mail.php components. **Recommendations** For ITFlow.org versions prior to commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378, update to a version that includes commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings.php, settings+company.php, settings defaults.php, settings integrations.php, settings invoice.php, settings localization.php, settings mail.php components until the update is applied.