Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49394 | Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view). |
Solution
The vulnerability has been fixed in idoit pro version 32.
Workaround
No workaround given by the vendor.
Wed, 18 Sep 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
I-doit
I-doit i-doit |
|
| CPEs | cpe:2.3:a:i-doit:i-doit:28:*:*:*:pro:*:*:* | |
| Vendors & Products |
I-doit
I-doit i-doit |
Thu, 12 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view). | |
| Title | Cross-site Scripting vulnerability in Idoit pro | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-12T12:54:52.748Z
Reserved: 2024-09-12T09:18:36.000Z
Link: CVE-2024-8750
Updated: 2024-09-12T12:54:49.066Z
Status : Analyzed
Published: 2024-09-12T12:15:54.007
Modified: 2024-09-18T20:38:42.123
Link: CVE-2024-8750
No data.
OpenCVE Enrichment
No data.
EUVD