Cross-Site Scripting (XSS) Vulnerability in AMSS++ version 4.31
CVE-2024-2593

6.1MEDIUM

Key Information:

Vendor

Amssplus

Status
Vendor
CVE Published:
18 March 2024

What is CVE-2024-2593?

A vulnerability exists in AMSS++ version 4.31 that fails to adequately encode user-controlled input. This oversight can lead to a Cross-Site Scripting (XSS) vulnerability, particularly through the '/amssplus/modules/book/main/bookdetail_group.php' endpoint, where attackers can exploit the 'b_id' parameter. By crafting a malicious URL, a remote attacker can target authenticated users, potentially allowing for the theft of their session cookie credentials. This situation highlights the importance of proper input validation and encoding to safeguard web applications against XSS attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AMSS++ 4.31

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.