Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2024-04-15T22:16:30.367Z

Updated: 2024-08-02T00:41:55.211Z

Reserved: 2024-02-26T15:32:28.515Z

Link: CVE-2024-27794

cve-icon Vulnrichment

Updated: 2024-08-02T00:41:55.211Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-15T23:15:06.890

Modified: 2024-07-03T01:50:49.393

Link: CVE-2024-27794

cve-icon Redhat

No data.