PT-2024-29572 · Tracks · Tracks

4Rdr

·

Published

2024-07-26

·

Updated

2024-07-29

·

CVE-2024-41805

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tracks versions prior to 2.7.1
Description The issue allows for reflected cross-site scripting, which enables the execution of malicious JavaScript in the context of a user's browser if that user clicks on a malicious link. This can lead to phishing attacks that could result in credential theft.
Recommendations For versions prior to 2.7.1, update to version 2.7.1 to resolve the issue. As a temporary workaround, consider avoiding clicking on links from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41805
GHSA-FP4P-59HR-3695

Affected Products

Tracks