Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-27671 Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.
Fixes

Solution

All vulnerabilities have been fixed in the new product version, CIGESv3. The manufacturer has developed a patch for those customers who have not migrated to the new version.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Atisoluciones
Atisoluciones ciges
CPEs cpe:2.3:a:atisoluciones:ciges:2.0:*:*:*:*:*:*:*
Vendors & Products Atisoluciones
Atisoluciones ciges

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T19:25:40.623Z

Reserved: 2024-03-20T11:33:50.640Z

Link: CVE-2024-2726

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:40.623Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-22T14:15:10.393

Modified: 2025-10-15T18:03:04.940

Link: CVE-2024-2726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:15:58Z