PT-2024-23624 · Easycorp · Easyadmin

Simoheinonen

·

Published

2024-03-29

·

Updated

2025-04-29

·

CVE-2024-3081

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EasyCorp EasyAdmin versions up to 4.8.9
Description A vulnerability was found in the Autocomplete function of the file assets/js/autocomplete.js, which can lead to cross-site scripting. The manipulation of the item argument is the cause of this issue. The attack can be launched remotely.
Recommendations For versions up to 4.8.9, upgrade to version 4.8.10 to address this issue. As a temporary workaround, consider disabling the Autocomplete function until a patch is available. Restrict access to the assets/js/autocomplete.js file to minimize the risk of exploitation. Avoid using the item argument in the affected Autocomplete function until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-3081

Affected Products

Easyadmin