Reflected XSS Vulnerability in Ajax Content Filter
CVE-2024-51717

7.1HIGH

Key Information:

Vendor
Perception System
Status
Ajax Content Filter
Vendor
CVE Published:
9 November 2024

Summary

The vulnerability in the Perception System Ajax Content Filter arises from improper neutralization of input during web page generation, specifically resulting in reflected cross-site scripting (XSS). This flaw permits an attacker to inject malicious scripts into webpages viewed by users, which can lead to unauthorized actions, data theft, or further compromise of the affected systems. The vulnerability impacts all versions of the Ajax Content Filter up to 1.0, warranting immediate attention from users to mitigate potential exploitation.

Affected Version(s)

Ajax Content Filter <= 1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thiennv (Patchstack Alliance)
.