Codebeamer vulnerable to Cross-Site Scripting (XSS) attack
CVE-2024-3951
7.1HIGH
What is CVE-2024-3951?
PTC Codebeamer presents a cross site scripting vulnerability that may enable an attacker to inject and subsequently execute malicious scripts within the affected application. This vulnerability poses significant risks as it can lead to unauthorized actions and the exposure of sensitive information. Implementing necessary security measures is crucial to mitigate potential attacks and protect the integrity of your systems.
Affected Version(s)
Codebeamer 0 <= 22.10 SP9
Codebeamer 0 <= 2.0.0.3
Codebeamer 2.1.0.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marek Holka (ETAS) reported this vulnerability to PTC.