Clibo Manager v1.1.9.1 vulnerable to stored XSS
CVE-2024-9198

5.4MEDIUM

Key Information:

Vendor
CVE Published:
26 September 2024

What is CVE-2024-9198?

Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture.

Affected Version(s)

Clibo Manager 1.1.9.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David Padilla Alvarado
.