Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 24 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jatos:jatos:3.9.3:*:*:*:*:*:*:* |
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jatos
Jatos jatos |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:jatos:jatos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jatos
Jatos jatos |
|
| Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-06T16:53:19.458Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-51379
Updated: 2024-11-06T16:53:10.940Z
Status : Analyzed
Published: 2024-11-05T19:15:07.373
Modified: 2025-06-24T13:28:19.803
Link: CVE-2024-51379
No data.
OpenCVE Enrichment
No data.