Cross-Site Scripting (XSS) Vulnerability in Janto by Impronta

Posted date 24/10/2024
Identificador
INCIBE-2024-0532
Importance
3 - Medium
Affected Resources

Janto, version 4.3r11.

Description

INCIBE has coordinated the publication of 1 medium severity vulnerability affecting Janto v4.3r11, a ticketing platform, which has been discovered by 6h4ack.

This vulnerability has been assigned the following code, CVSS v3.1 base score, CVSS vector and CWE vulnerability type:

  • CVE-2024-10332: CVSS v3.1: 6.1 | CVSS AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. | CWE-79.
Solution

The vulnerability has been fixed by the Impronta team in version r12.

Detail

CVE-2024-10332: A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the endpoint “/abonados/public/janto/main.php”.

References list