PT-2024-26706 · Enea · Enea Overclokk Stellissimo Text Box

Cronus

·

Published

2024-06-08

·

Updated

2024-07-25

·

CVE-2024-35752

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Enea Overclokk Stellissimo Text Box versions through 1.1.4
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS), allowing Stored XSS. This enables attackers to inject malicious scripts into web pages, potentially affecting users who access these pages.
Recommendations For versions through 1.1.4, update to a version that fixes the Stored XSS vulnerability to prevent exploitation. As a temporary workaround, consider restricting user input in the Stellissimo Text Box to minimize the risk of Stored XSS attacks until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-35752

Affected Products

Enea Overclokk Stellissimo Text Box