PT-2024-10472 · Koji+1 · Koji+1

James Taliaferro

·

Published

2024-12-23

·

Updated

2025-02-07

·

CVE-2024-9427

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Koji (affected versions not specified)
Description The issue is related to improper neutralization of input during web page generation, allowing for a reflected XSS attack. An unsanitized input can lead to an XSS attack, where harmful JavaScript code from a malicious link could be reflected in the resulting web page. However, due to existing XSS protections in the code, it is not expected to be able to submit an action or make a change in Koji.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-01015
CVE-2024-9427
GHSA-G2VG-8HFG-79VJ

Affected Products

Koji
Red Os