HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
Fixes

Solution

All vulnerabilities have been fixed in the new product version, CIGESv3. The manufacturer has developed a patch for those customers who have not migrated to the new version.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T19:25:40.608Z

Reserved: 2024-03-20T11:33:51.453Z

Link: CVE-2024-2727

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:40.608Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-22T14:15:10.593

Modified: 2024-11-21T09:10:23.127

Link: CVE-2024-2727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:22:34Z