PT-2024-21965 · Bonitasoft · Bonita

Published

2024-03-31

·

Updated

2024-11-08

·

CVE-2024-27609

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Bonita versions prior to 2023.2-u2 Bonita versions prior to 10.1.0.W11
Description The issue allows stored XSS via a UI screen in the administration panel. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 2023.2-u2, update to version 2023.2-u2 or later. For versions prior to 10.1.0.W11, update to version 10.1.0.W11 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-27609
GHSA-8VJ9-5V5Q-FHCH

Affected Products

Bonita