PT-2025-3086 · Monicahq · Monicahq

Nicolas Gula

·

Published

2025-01-10

·

Updated

2025-01-13

·

CVE-2024-54996

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MonicaHQ version 4.1.2
Description The issue concerns multiple authenticated Client-Side Injection vulnerabilities in MonicaHQ. These vulnerabilities occur through the title and description parameters at the "/people/ID/reminders/create" API endpoint. The exploitation of this issue can be done by authenticated users, which may limit the impact.
Recommendations For MonicaHQ version 4.1.2, consider disabling the functionality that allows users to input data into the title and description parameters at the "/people/ID/reminders/create" API endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the title and description parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-54996

Affected Products

Monicahq