Xinhu RockOA v2.6.3 Vulnerable to Reflected Cross-Site Scripting (XSS)
CVE-2024-37623

6.1MEDIUM

Key Information:

Vendor

Xinhu

Status
Vendor
CVE Published:
17 June 2024

What is CVE-2024-37623?

The Xinhu RockOA version 2.6.3 contains a reflected cross-site scripting vulnerability located within the /kaoqin/tpl_kaoqin_locationchange.html component. This flaw enables malicious actors to manipulate input fields, potentially allowing them to inject and execute arbitrary scripts in the context of a user's browser. Such vulnerabilities can lead to session hijacking, data theft, or unauthorized actions performed in the affected user’s session, emphasizing the importance of implementing robust input validation and output encoding practices.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.