Cross-Site Scripting (XSS) Vulnerability in AMSS++ version 4.31
CVE-2024-2598

6.1MEDIUM

Key Information:

Vendor

Amssplus

Status
Vendor
CVE Published:
18 March 2024

What is CVE-2024-2598?

A security vulnerability has been identified in AMSS++ version 4.31, which fails to properly sanitize user-controlled input. This flaw manifests as a Cross-Site Scripting (XSS) vulnerability in the file /amssplus/modules/book/main/select_send_2.php, affecting multiple input parameters. Consequently, an attacker could craft a malicious URL and send it to an authenticated user, potentially leading to the theft of session cookies and unauthorized access to user accounts. It is crucial for users of AMSS++ version 4.31 to be aware of this vulnerability and to apply any available patches to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AMSS++ 4.31

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.