PT-2024-25763 · Konga · Konga

Published

2024-05-14

·

Updated

2025-06-13

·

CVE-2024-34243

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Konga version 0.14.9
Description The issue allows for Cross Site Scripting (XSS) via the username parameter.
Recommendations For Konga version 0.14.9, avoid using the username parameter until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-34243
GHSA-93PF-MRC8-4G3H

Affected Products

Konga