PT-2024-24244 · Italtel · Italtel Embrace

Fabio Romano

+3

·

Published

2024-05-21

·

Updated

2024-07-26

·

CVE-2024-31847

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Italtel Embrace version 1.6.4
Description A stored cross-site scripting (XSS) issue allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user input without sanitization.
Recommendations For Italtel Embrace version 1.6.4, consider disabling the GET parameter that allows user input until a patch is available to prevent exploitation of the stored cross-site scripting issue. Restrict access to the affected parameter to minimize the risk of arbitrary web script or HTML injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-31847

Affected Products

Italtel Embrace