Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34034 | A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 03 Dec 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jpress
Jpress jpress |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:jpress:jpress:5.1.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Jpress
Jpress jpress |
Fri, 29 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Guizhou Xiaoma Technology jpress Avatar upload cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-11-29T17:08:36.529Z
Reserved: 2024-11-28T17:04:28.759Z
Link: CVE-2024-11971
Updated: 2024-11-29T17:01:23.574Z
Status : Analyzed
Published: 2024-11-28T22:15:15.090
Modified: 2024-12-03T20:04:46.493
Link: CVE-2024-11971
No data.
OpenCVE Enrichment
No data.
EUVD