Description
Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the campaign is removed from the menu.
No analysis available yet.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27170 | Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the campaign is removed from the menu. |
References
History
Wed, 26 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgophish
Getgophish gophish |
|
| CPEs | cpe:2.3:a:getgophish:gophish:0.12.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgophish
Getgophish gophish |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T19:03:39.398Z
Reserved: 2024-03-06T07:45:08.547Z
Link: CVE-2024-2211
Updated: 2024-08-01T19:03:39.398Z
Status : Analyzed
Published: 2024-03-06T11:15:07.233
Modified: 2025-02-26T15:14:55.753
Link: CVE-2024-2211
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD