PT-2024-31848 · Solvait · Solvait

Abdulwahab Alismaeel

·

Published

2024-09-30

·

Updated

2024-10-04

·

CVE-2024-45920

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Solvait version 24.4.2
Description A Stored Cross-Site Scripting (XSS) vulnerability allows remote attackers to inject malicious scripts into the application due to insufficient input validation and sanitization in the "Intrest" feature.
Recommendations For Solvait version 24.4.2, consider disabling the "Intrest" feature until a patch is available to prevent exploitation of the Stored Cross-Site Scripting (XSS) vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-45920

Affected Products

Solvait