Clio Grow Vulnerable to Reflected XSS Attacks
CVE-2024-49276
7.1HIGH
What is CVE-2024-49276?
An improper neutralization of input during web page generation in Clio Grow by Themis Solutions, Inc. allows for reflected Cross-Site Scripting (XSS) attacks. This vulnerability enables an attacker to execute arbitrary Javascript code within a user's browser session, potentially leading to session hijacking, cookie theft, or unauthorized actions on behalf of the user. This issue is present in Clio Grow versions from n/a through 1.0.2, making it critical for users to ensure they are using a patched version.
Affected Version(s)
Clio Grow <= 1.0.2