PT-2024-24026 · Francoisjacquet · Rosariosis
Louay Khammassi
·
Published
2024-04-01
·
Updated
2024-08-01
·
CVE-2024-3138
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
francoisjacquet RosarioSIS version 11.5.1
Description
A disputed issue affects the Add Portal Note component, leading to cross-site scripting. The attack can be initiated remotely. The vendor notes that the PDF is opened by the browser app in a sandbox, which should prevent website data from being accessible.
Recommendations
For version 11.5.1, consider disabling the Add Portal Note component until the issue is resolved, and verify the effectiveness of sandbox isolation to minimize potential risks.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rosariosis