PT-2024-23652 · Unknown · Rageframe2

Hebing123

·

Published

2024-04-11

·

Updated

2024-10-27

·

CVE-2024-30879

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RageFrame2 version 2.6.43
Description The issue allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the boxId parameter in the image cropping function. This is a Reflected Cross Site Scripting (XSS) vulnerability.
Recommendations For RageFrame2 version 2.6.43, consider disabling the image cropping function until a patch is available to prevent exploitation of the boxId parameter. Restrict access to this function to minimize the risk of sensitive information being obtained by attackers.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-30879

Affected Products

Rageframe2