Description
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user.
No analysis available yet.
Remediation
Vendor Solution
There is no solution reported at the moment.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43977 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user. |
References
History
Wed, 15 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adive
Adive framework |
|
| CPEs | cpe:2.3:a:adive:framework:2.0.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Adive
Adive framework |
Thu, 15 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-15T14:58:57.161Z
Reserved: 2024-04-30T07:46:12.006Z
Link: CVE-2024-4336
Updated: 2024-08-01T20:40:46.461Z
Status : Analyzed
Published: 2024-04-30T10:15:07.943
Modified: 2025-10-15T14:16:48.890
Link: CVE-2024-4336
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD