PT-2024-29572 · Tracks · Tracks
4Rdr
·
Published
2024-07-26
·
Updated
2024-07-29
·
CVE-2024-41805
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tracks versions prior to 2.7.1
Description
The issue allows for reflected cross-site scripting, which enables the execution of malicious JavaScript in the context of a user's browser if that user clicks on a malicious link. This can lead to phishing attacks that could result in credential theft.
Recommendations
For versions prior to 2.7.1, update to version 2.7.1 to resolve the issue.
As a temporary workaround, consider avoiding clicking on links from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tracks