Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.
Fixes

Solution

All vulnerabilities have been fixed in the new product version, CIGESv3. The manufacturer has developed a patch for those customers who have not migrated to the new version.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T19:25:40.623Z

Reserved: 2024-03-20T11:33:50.640Z

Link: CVE-2024-2726

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:40.623Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-22T14:15:10.393

Modified: 2024-11-21T09:10:23.000

Link: CVE-2024-2726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:15:58Z