PT-2024-36744 · Userpro · Userpro

Rafie Muhammad

·

Published

2024-12-31

·

Updated

2025-01-05

·

CVE-2024-56210

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Userpro versions prior to 5.1.9
Description The issue involves improper neutralization of input during web page generation, leading to a Cross-site Scripting (XSS) vulnerability, specifically Reflected XSS. This allows attackers to inject malicious scripts into web pages.
Recommendations For versions prior to 5.1.9, update to a version later than 5.1.9 to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of exploitation. Avoid using vulnerable parameters in affected API endpoints until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-56210

Affected Products

Userpro