PT-2024-39327 · Unknown · Scriptcase

Rafael Pedrero

·

Published

2024-09-24

·

Updated

2024-09-30

·

CVE-2024-8942

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Scriptcase version 9.4.019
Description: The issue is a Cross-Site Scripting (XSS) due to the lack of input validation, affecting the id form msg title parameter, among others. This could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.
Recommendations: For Scriptcase version 9.4.019, as a temporary workaround, consider restricting the use of the id form msg title parameter until a patch is available. Avoid using this parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-8942

Affected Products

Scriptcase