Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre.
This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19450 | Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 10 Feb 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gallagher
Gallagher command Centre |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gallagher
Gallagher command Centre |
Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2024-08-01T22:27:36.320Z
Reserved: 2024-02-05T04:16:47.986Z
Link: CVE-2024-21838
Updated: 2024-08-01T22:27:36.320Z
Status : Analyzed
Published: 2024-03-05T03:15:06.280
Modified: 2025-02-10T22:33:35.600
Link: CVE-2024-21838
No data.
OpenCVE Enrichment
No data.
EUVD