PT-2024-30198 · Syspass · Syspass

Nuxsmin

·

Published

2024-09-03

·

Updated

2024-09-12

·

CVE-2024-42904

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SysPass versions 3.2.x
Description A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the name parameter at the "/Controllers/ClientController.php" endpoint. This enables attackers to potentially execute arbitrary code.
Recommendations For SysPass version 3.2.x, update the system as soon as possible and validate inputs to prevent exploitation. Consider temporarily restricting access to the ClientController.php until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42904

Affected Products

Syspass