PT-2024-30259 · Rws · Rws Multitrans

Published

2024-09-18

·

Updated

2024-09-30

·

CVE-2024-43025

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RWS MultiTrans versions 7.0.23324.2 and earlier
Description The issue allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.
Recommendations For RWS MultiTrans versions 7.0.23324.2 and earlier, update to a version later than 7.0.23324.2 to resolve the issue. As a temporary workaround, consider restricting the ability to inject HTML code into e-mails to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-43025

Affected Products

Rws Multitrans