PT-2024-38093 · Unknown · Dingo Dlibra

Kacper Rybczyåski

+1

·

Published

2024-11-14

·

Updated

2024-11-15

·

CVE-2024-7124

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/AU:Y/R:A/U:Green
Name of the Vulnerable Software and Affected Versions DInGO dLibra software versions 6.0 through 6.3.19
Description The issue is related to improper neutralization of input during web page generation, allowing a Reflected Cross-Site Scripting (XSS) attack. This occurs in the filter parameter of the "indexsearch" endpoint. An attacker could trick a user into using a crafted URL, causing a script to run in the user's browser.
Recommendations For versions 6.0 through 6.3.19, update to version 6.3.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the "indexsearch" endpoint or avoiding the use of the filter parameter until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-7124

Affected Products

Dingo Dlibra