PT-2024-34419 · Unknown · Hopetree Izone Lts
V9D0Go
·
Published
2024-11-08
·
Updated
2024-11-12
·
CVE-2024-50810
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
hopetree izone lts version c011b48
Description:
The issue is related to a Cross Site Scripting (XSS) vulnerability in the article comment function. Specifically, the
AddCommintView() function in appscommentviews.py does not securely filter user input, rendering it directly to the frontend page through templates. This allows for potential XSS attacks.Recommendations:
For version c011b48, ensure that the
AddCommintView() function securely filters user input to prevent XSS attacks. As a temporary workaround, consider disabling the AddCommintView() function until a patch is available. Restrict access to the comment functionality to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hopetree Izone Lts