PT-2024-33186 · Unknown · Collabtive

Anoncoder01

·

Published

2024-10-22

·

Updated

2024-10-25

·

CVE-2024-48706

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Collabtive version 3.1
Description The issue is related to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the managemessage.php file and managetask.php file respectively. This allows for potential exploitation.
Recommendations For Collabtive version 3.1, consider restricting access to the title parameter in the affected files until a patch is available. As a temporary workaround, avoid using the title parameter with action=add or action=editform in the managemessage.php and managetask.php files.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-48706

Affected Products

Collabtive