Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Oct 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scriptcase
Scriptcase scriptcase |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:scriptcase:scriptcase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Scriptcase
Scriptcase scriptcase |
|
| Metrics |
cvssV3_1
|
Tue, 01 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-01T19:36:23.417Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46083
Updated: 2024-10-01T19:35:25.307Z
Status : Analyzed
Published: 2024-10-01T19:15:09.013
Modified: 2025-04-28T17:16:59.523
Link: CVE-2024-46083
No data.
OpenCVE Enrichment
No data.