Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jatos
Jatos jatos |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:jatos:jatos:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jatos
Jatos jatos |
|
Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-05T00:00:00
Updated: 2024-11-06T16:53:19.458Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-51379
Vulnrichment
Updated: 2024-11-06T16:53:10.940Z
NVD
Status : Awaiting Analysis
Published: 2024-11-05T19:15:07.373
Modified: 2024-11-06T18:17:17.287
Link: CVE-2024-51379
Redhat
No data.