CVE-2024-51379
CVE-2024-51379
Título es
CVE-2024-51379
Mar, 05/11/2024 – 19:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-51379
Descripción en
Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.
05/11/2024
05/11/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off