CVE Published: 14/11/2024 |
CVE Updated: 14/11/2024 |
CVE Year: 2024 Source: CERT-PL |
Vendor: Poznan Supercomputing and Networking Center |
Product: DInGO dLIbra Status : PUBLISHED
CVE-2024-7124 Description
Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter \'filter\' in the endpoint \'indexsearch\' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user\'s browser. This issue affects DInGO dLibra software in versions from 6.0 before 6.3.20.
CWE-ID: CWE-79 CWE Name: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or
Cross-site Scripting
) Source: Poznan Supercomputing and Networking Center
Common Attack Pattern Enumeration and Classification (CAPEC)