CVE-2024-51380
CVE-2024-51380
Título es
CVE-2024-51380
Mar, 05/11/2024 – 19:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-51380
Descripción en
Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin user accesses the study's properties, the injected script is executed in the admin's browser, which could lead to unauthorized actions, including account compromise and privilege escalation.
05/11/2024
05/11/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off