Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view).
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
I-doit
I-doit i-doit |
|
| CPEs | cpe:2.3:a:i-doit:i-doit:28:*:*:*:pro:*:*:* | |
| Vendors & Products |
I-doit
I-doit i-doit |
Thu, 12 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view). | |
| Title | Cross-site Scripting vulnerability in Idoit pro | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2024-09-12T11:38:24.912Z
Updated: 2024-09-12T12:54:52.748Z
Reserved: 2024-09-12T09:18:36.000Z
Link: CVE-2024-8750
Updated: 2024-09-12T12:54:49.066Z
Status : Analyzed
Published: 2024-09-12T12:15:54.007
Modified: 2024-09-18T20:38:42.123
Link: CVE-2024-8750
No data.