PT-2024-37572 · Labvantage · Labvantage Lims

Farouk

·

Published

2024-06-27

·

Updated

2024-09-17

·

CVE-2024-6368

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LabVantage LIMS version 2017 WPML (affected versions not specified)
Description A problematic issue affects the processing of the file "/labvantage/rc?command=page" of the component POST Request Handler. The manipulation of the argument param1 leads to cross-site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This issue may allow an attacker to execute arbitrary code on the vulnerable server.
Recommendations For LabVantage LIMS version 2017, consider disabling the param1 argument in the POST Request Handler until a patch is available. For WPML, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6368

Affected Products

Labvantage Lims