Stored XSS Vulnerability in Cervantes 0.5-alpha
CVE-2024-42055

5.4MEDIUM

Key Information:

Vendor

Cervantes

Status
Vendor
CVE Published:
28 July 2024

What is CVE-2024-42055?

A stored cross-site scripting (XSS) vulnerability has been identified in the Cervantes software, specifically affecting version 0.5-alpha. This critical security flaw allows an attacker to insert malicious scripts into files that are then uploaded and stored within the application. As a result, unsuspecting users who access the affected files may inadvertently execute these scripts in their web browsers, leading to unauthorized actions and the potential compromise of user data. Ensuring secure file upload practices and proper input validation are essential to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.