PT-2024-26519 · Finesoft · Finesoft

Dabaizhizhu

·

Published

2024-05-30

·

Updated

2024-05-30

·

CVE-2024-35504

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FineSoft version 8.0
Description A cross-site scripting (XSS) issue in the login page allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL:errorname parameter after a failed login attempt.
Recommendations For FineSoft version 8.0, consider restricting access to the login page or validating user input to prevent malicious payloads from being injected into the errorname parameter until a fix is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-35504

Affected Products

Finesoft