PT-2024-35443 · Unknown · Qiwen Netdisk

Somurim

·

Published

2024-05-23

·

Updated

2024-06-04

·

CVE-2024-5279

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Qiwen Netdisk versions up to 1.4.0
Description A vulnerability was found in the File Rename Handler component, which can be exploited to lead to cross-site scripting. The issue can be triggered by manipulating the input with a malicious string, such as <img src="" onerror="alert(document.cookie)">. This allows for remote attacks.
Recommendations For Qiwen Netdisk versions up to 1.4.0, update to a version later than 1.4.0 to resolve the issue. As a temporary workaround, consider restricting the use of the File Rename Handler component to minimize the risk of exploitation. Avoid using potentially malicious input in the affected component until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5279

Affected Products

Qiwen Netdisk