Cross Site Scripting in

UI Request/Response Validation

in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-31913 Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-08-01T20:05:08.445Z

Reserved: 2024-04-04T17:01:23.280Z

Link: CVE-2024-3323

cve-icon Vulnrichment

Updated: 2024-08-01T20:05:08.445Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-17T19:15:08.177

Modified: 2024-11-21T09:29:23.787

Link: CVE-2024-3323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:15:57Z