Description
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.
No analysis available yet.
Remediation
Vendor Solution
There is no solution reported at the moment.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43978 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user. |
References
History
Wed, 15 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adive
Adive framework |
|
| CPEs | cpe:2.3:a:adive:framework:2.0.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Adive
Adive framework |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-03T18:16:53.294Z
Reserved: 2024-04-30T07:46:33.495Z
Link: CVE-2024-4337
Updated: 2024-08-01T20:40:47.108Z
Status : Analyzed
Published: 2024-04-30T10:15:08.147
Modified: 2025-10-15T14:13:23.520
Link: CVE-2024-4337
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD