PT-2024-33187 · Unknown · Collabtive

Anoncoder01

·

Published

2024-10-22

·

Updated

2024-10-25

·

CVE-2024-48707

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Collabtive version 3.1
Description The issue concerns Cross-site scripting (XSS) via the name parameter. This occurs under specific conditions: (a) when action equals add or action equals edit within the managemilestone.php file, and (b) when action equals addpro within the admin.php file. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Collabtive version 3.1, consider restricting access to the managemilestone.php and admin.php files to minimize the risk of exploitation. Avoid using the name parameter in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-48707

Affected Products

Collabtive