Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49923 | A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 01 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ofcms Project
Ofcms Project ofcms |
|
| CPEs | cpe:2.3:a:ofcms_project:ofcms:1.1.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ofcms Project
Ofcms Project ofcms |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | OFCMS add.json add cross site scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-27T21:36:38.939Z
Reserved: 2024-10-01T14:45:19.683Z
Link: CVE-2024-9411
Updated: 2024-10-01T20:13:46.729Z
Status : Modified
Published: 2024-10-01T20:15:05.630
Modified: 2025-08-27T22:15:56.680
Link: CVE-2024-9411
No data.
OpenCVE Enrichment
No data.
EUVD