Description
A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the pageId parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 25 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-25T15:34:53.063Z
Reserved: 2024-04-23T00:00:00.000Z
Link: CVE-2024-33328
Updated: 2024-08-02T02:27:53.704Z
Status : Deferred
Published: 2024-06-26T19:15:13.373
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-33328
No data.
OpenCVE Enrichment
No data.
Weaknesses