PT-2024-38527 · Ocomon · Ocomon
Hydd3N
·
Published
2024-08-13
·
Updated
2024-08-17
·
CVE-2024-7709
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OcoMon versions 4.0RC1 through 5.0RC1
Description
A problematic issue has been found in the URL Handler component, specifically affecting the file /includes/common/require access recovery.php. This issue leads to cross site scripting, allowing an attack to be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations
For OcoMon versions 4.0RC1 through 4.0, upgrade to version 4.0.1 to address this issue.
For OcoMon version 5.0RC1, upgrade to version 5.0 to address this issue.
As a temporary workaround, consider restricting access to the /includes/common/require access recovery.php file until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ocomon