HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hyperview
Hyperview geoportal Toolkit |
|
CPEs | cpe:2.3:a:hyperview:geoportal_toolkit:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hyperview
Hyperview geoportal Toolkit |
|
Metrics |
cvssV3_1
|
Fri, 06 Sep 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HyperView Geoportal Toolkit in versions though 8.2.4 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. | HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. |
Wed, 28 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 28 Aug 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HyperView Geoportal Toolkit in versions though 8.2.4 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. | |
Title | Reflected XSS in HyperView Geoportal Toolkit | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-08-28T11:50:20.929Z
Updated: 2024-09-06T12:48:48.832Z
Reserved: 2024-07-02T12:01:59.302Z
Link: CVE-2024-6450
Vulnrichment
Updated: 2024-08-28T13:13:36.859Z
NVD
Status : Analyzed
Published: 2024-08-28T12:15:06.507
Modified: 2024-09-12T15:42:45.430
Link: CVE-2024-6450
Redhat
No data.