A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site.
This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others.
Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 23 Sep 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netcat
Netcat netcat Content Management System |
|
| CPEs | cpe:2.3:a:netcat:netcat_content_management_system:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Netcat
Netcat netcat Content Management System |
|
| Metrics |
cvssV3_1
|
Thu, 19 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch. | |
| Title | Netcat CMS: reflected cross-site scripting in openstat module | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Kaspersky
Published: 2024-09-19T16:35:55.844Z
Updated: 2024-09-19T18:23:52.427Z
Reserved: 2024-09-10T12:27:48.141Z
Link: CVE-2024-8652
Updated: 2024-09-19T18:23:49.155Z
Status : Analyzed
Published: 2024-09-19T17:15:15.360
Modified: 2024-09-23T17:53:49.197
Link: CVE-2024-8652
No data.