PT-2024-37272 · Eliz · Eliz Software Panel

Serhat Yapici

·

Published

2024-09-18

·

Updated

2024-09-26

·

CVE-2024-5959

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions: Eliz Software Panel versions prior to 2.3.24
Description: The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for Stored XSS attacks.
Recommendations: For versions prior to 2.3.24, update to version 2.3.24 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-5959

Affected Products

Eliz Software Panel