Cross Site Scripting Vulnerability in 1.8.4.5
CVE-2024-9007
Key Information:
- Vendor
Jeanmarc77
- Status
- Vendor
- CVE Published:
- 19 September 2024
Badges
What is CVE-2024-9007?
A security vulnerability has been identified in the JeanMarc77 123Solar application version 1.8.4.5, specifically within the file detailed.php. This flaw stems from improper handling of the 'date1' argument, which allows for cross site scripting (XSS) attacks. An attacker can exploit this vulnerability remotely, potentially leading to the execution of malicious scripts in the context of the user's session. The exploit has been disclosed publicly, highlighting the urgency for users to mitigate risk by applying the provided patch (commit ID: 94bf9ab7ad0ccb7fbdc02f172f37f0e2ea08d48f). Taking immediate action to secure systems against this vulnerability is strongly advised.
Affected Version(s)
123solar 1.8.4.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved