Cross-site Scripting Vulnerability in FitNesse Releases Up to 20241026
CVE-2024-39610

6.1MEDIUM

Key Information:

Vendor

Unclebob

Status
Vendor
CVE Published:
15 November 2024

What is CVE-2024-39610?

Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.

Affected Version(s)

FitNesse releases prior to 20241026

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.