PT-2024-21278 · Tvrock · Tvrock

Published

2024-03-26

·

Updated

2024-10-31

·

CVE-2024-26018

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TvRock version 0.9t8a
Description A cross-site scripting vulnerability exists, allowing an arbitrary script to be executed on the web browser of the user accessing the website that uses the product. The developer was unreachable, and users should consider stopping the use of TvRock 0.9t8a.
Recommendations For TvRock version 0.9t8a, consider stopping the use of this version as the developer is unreachable and no fix is available. As a temporary workaround, consider implementing additional security measures to restrict the execution of arbitrary scripts in the web browser.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-26018

Affected Products

Tvrock