Cross-Site Scripting (XSS) Vulnerability in Janto by Impronta
Posted date 24/10/2024
Identificador
INCIBE-2024-0532
Importance
3 - Medium
Affected Resources
Janto, version 4.3r11.
Description
INCIBE has coordinated the publication of 1 medium severity vulnerability affecting Janto v4.3r11, a ticketing platform, which has been discovered by 6h4ack.
This vulnerability has been assigned the following code, CVSS v3.1 base score, CVSS vector and CWE vulnerability type:
- CVE-2024-10332: CVSS v3.1: 6.1 | CVSS AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. | CWE-79.
Solution
The vulnerability has been fixed by the Impronta team in version r12.
Detail
CVE-2024-10332: A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the endpoint “/abonados/public/janto/main.php”.
References list
Etiquetas