PT-2024-24026 · Francoisjacquet · Rosariosis

Louay Khammassi

·

Published

2024-04-01

·

Updated

2024-08-01

·

CVE-2024-3138

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions francoisjacquet RosarioSIS version 11.5.1
Description A disputed issue affects the Add Portal Note component, leading to cross-site scripting. The attack can be initiated remotely. The vendor notes that the PDF is opened by the browser app in a sandbox, which should prevent website data from being accessible.
Recommendations For version 11.5.1, consider disabling the Add Portal Note component until the issue is resolved, and verify the effectiveness of sandbox isolation to minimize potential risks.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-3138
GHSA-R32G-W9CV-9FGC

Affected Products

Rosariosis