PT-2024-28024 · Ibarn · Ibarn

Hebing123

·

Published

2024-06-17

·

Updated

2025-04-30

·

CVE-2024-38470

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions iBarn version 1.5
Description A reflected cross-site scripting (XSS) issue was found, which can be triggered via the search parameter at the "/own.php" endpoint.
Recommendations For version 1.5, consider restricting access to the /own.php endpoint or avoiding the use of the search parameter until a fix is available. As a temporary workaround, input validation and sanitization of the search parameter can help minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-38470

Affected Products

Ibarn