PT-2024-16710 · Grand Vice Info · Webopac

Ming-Hung

+3

·

Published

2024-11-11

·

Updated

2024-11-18

·

CVE-2024-11021

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Webopac from Grand Vice info (affected versions not specified)
Description The issue is a Stored Cross-site Scripting vulnerability, allowing remote attackers with regular privileges to inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-11021

Affected Products

Webopac