Cross Site Scripting Vulnerability in thinkgem JeeSite 5.3

CVE-2024-8112
6.1MEDIUM

Key Information

Vendor
Thinkgem
Status
Jeesite
Vendor
CVE Published:
23 August 2024

Summary

A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The manipulation of the argument skinName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected Version(s)

JeeSite = 5.3

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Risk change from: null to: 4.3 - (MEDIUM)

  • VulDB entry last update

  • Vulnerability Reserved.

  • VulDB entry created

  • Advisory disclosed

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database

Credit

VulDB Gitee Analyzer
.