In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Fortra
Published: 2024-03-13T14:15:54.156Z
Updated: 2024-08-01T23:36:21.639Z
Reserved: 2024-02-06T21:23:57.925Z
Link: CVE-2024-25155
Vulnrichment
Updated: 2024-08-01T23:36:21.639Z
NVD
Status : Awaiting Analysis
Published: 2024-03-13T15:15:51.700
Modified: 2024-03-13T18:16:18.563
Link: CVE-2024-25155
Redhat
No data.