PT-2024-22191 · Typps · Typps Calendarista Basic Edition

Mochamad Sofyan

·

Published

2024-03-21

·

Updated

2024-03-22

·

CVE-2024-27993

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Typps Calendarista Basic Edition versions 3.0.2 and earlier
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting. This allows for potential malicious script injection into web pages generated by the application.
Recommendations For Typps Calendarista Basic Edition versions 3.0.2 and earlier, update to a version later than 3.0.2 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-27993

Affected Products

Typps Calendarista Basic Edition