PT-2024-23652 · Unknown · Rageframe2
Hebing123
·
Published
2024-04-11
·
Updated
2024-10-27
·
CVE-2024-30879
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RageFrame2 version 2.6.43
Description
The issue allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the
boxId parameter in the image cropping function. This is a Reflected Cross Site Scripting (XSS) vulnerability.Recommendations
For RageFrame2 version 2.6.43, consider disabling the image cropping function until a patch is available to prevent exploitation of the
boxId parameter. Restrict access to this function to minimize the risk of sensitive information being obtained by attackers.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rageframe2