Codebeamer vulnerable to Cross-Site Scripting (XSS) attack
CVE-2024-3951

7.1HIGH

Key Information:

Vendor

Ptc

Vendor
CVE Published:
8 May 2024

What is CVE-2024-3951?

PTC Codebeamer presents a cross site scripting vulnerability that may enable an attacker to inject and subsequently execute malicious scripts within the affected application. This vulnerability poses significant risks as it can lead to unauthorized actions and the exposure of sensitive information. Implementing necessary security measures is crucial to mitigate potential attacks and protect the integrity of your systems.

Affected Version(s)

Codebeamer 0 <= 22.10 SP9

Codebeamer 0 <= 2.0.0.3

Codebeamer 2.1.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marek Holka (ETAS) reported this vulnerability to PTC.
.