PT-2024-21278 · Tvrock · Tvrock
Published
2024-03-26
·
Updated
2024-10-31
·
CVE-2024-26018
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TvRock version 0.9t8a
Description
A cross-site scripting vulnerability exists, allowing an arbitrary script to be executed on the web browser of the user accessing the website that uses the product. The developer was unreachable, and users should consider stopping the use of TvRock 0.9t8a.
Recommendations
For TvRock version 0.9t8a, consider stopping the use of this version as the developer is unreachable and no fix is available. As a temporary workaround, consider implementing additional security measures to restrict the execution of arbitrary scripts in the web browser.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tvrock