Arbitrary Code Execution via Cross-Site Scripting (XSS) in dcat-admin
CVE-2024-29644

6.1MEDIUM

Key Information:

Vendor

dcat-admin

Vendor
CVE Published:
26 March 2024

What is CVE-2024-29644?

A Cross Site Scripting vulnerability exists in Dcat-Admin, which is a web application framework. This flaw allows a remote attacker to inject malicious scripts through the user login box, potentially leading to unauthorized execution of arbitrary code. Attackers exploiting this vulnerability could compromise user accounts and perform unauthorized actions on behalf of legitimate users, making it critical for organizations using this product to implement necessary security measures and updates.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.