PT-2024-21418 · Bonitasoft · Bonitasoft

Tomas Castro Rojas

·

Published

2024-02-27

·

Updated

2025-09-17

·

CVE-2024-26542

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bonitasoft, S.A versions prior to 7.14.8 Bonitasoft, S.A versions prior to 7.15.7 Bonitasoft, S.A versions prior to 8.0.3 Bonitasoft, S.A versions prior to 9.0.2
Description The issue allows attackers to execute arbitrary code via a crafted payload to the Groups Display name field. This is a Cross Site Scripting vulnerability.
Recommendations For versions prior to 7.14.8, update to version 7.14.8 or later. For versions prior to 7.15.7, update to version 7.15.7 or later. For versions prior to 8.0.3, update to version 8.0.3 or later. For versions prior to 9.0.2, update to version 9.0.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-26542

Affected Products

Bonitasoft