Description
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.
Published: 2024-09-24
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The vulnerability has been fixed in the latest version.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-49499 Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.
History

Mon, 30 Sep 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Scriptcase
Scriptcase scriptcase
CPEs cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*
Vendors & Products Scriptcase
Scriptcase scriptcase

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 12:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.
Title Cross-site Scripting vulnerability on Scriptcase
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Scriptcase Scriptcase
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-24T13:26:07.233Z

Reserved: 2024-09-17T09:43:48.913Z

Link: CVE-2024-8942

cve-icon Vulnrichment

Updated: 2024-09-24T13:26:01.461Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-25T01:15:48.483

Modified: 2024-09-30T17:39:28.417

Link: CVE-2024-8942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses