CVE-2024-28142
Last modified
CVE-2024-28142 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "File Name" page (/cgi/uset.cgi?-cfilename) in the User Settings menu improperly filters the "file name" and wildcard character input field. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "File Name" page (/cgi/uset.cgi?-cfilename) in the User Settings menu improperly filters the "file name" and wildcard character input field. By exploiting the wildcard character feature, attackers are able to store arbitrary Javascript code which is being triggered if the page is viewed afterwards, e.g. by higher privileged users such as admins. This attack can even be performed without being logged in because the affected functions are not fully protected. Without logging in, only the file name parameter of the "Default" User can be changed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-28142?
How severe is CVE-2024-28142?
How do I fix CVE-2024-28142?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-28137 …7.8
- CVE-2024-28138An unauthenticated attacker with network access to the affec…7.3
- CVE-2024-28139The www-data user can elevate its privileges because sudo is…8.8
- CVE-2024-2814A vulnerability was found in Tenda AC15 15.03.20_multi. It h…9.8
- CVE-2024-28140The scanner device boots into a kiosk mode by default and op…6.1
- CVE-2024-28141The web application is not protected against cross-site requ…6.3
- CVE-2024-28143The password change function at /cgi/admin.cgi does not requ…8.4
- CVE-2024-28144An attacker who can spoof the IP address and the User-Agent …5.5
- CVE-2024-28145An unauthenticated attacker can perform an SQL injection by …5.9
- CVE-2024-28146The application uses several hard-coded credentials to encry…8.4
- CVE-2024-28147An authenticated user can upload arbitrary files in the uplo…7.4
- CVE-2024-28148An authenticated user could potentially access metadata for …4.3
Are you affected by CVE-2024-28142?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
