CVE-2024-4731
Last modified
CVE-2024-4731 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A vulnerability classified as problematic was found in Campcodes Legal Case Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/role. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic was found in Campcodes Legal Case Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/role. The manipulation of the argument slug leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263809 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Campcodes | Legal Case Management System | 1.0 |
References
- https://vuldb.com/?ctiid.263809Permissions Required, VDB Entry
- https://vuldb.com/?id.263809Permissions Required, VDB Entry
- https://vuldb.com/?submit.331995Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.263809Permissions Required, VDB Entry
- https://vuldb.com/?id.263809Permissions Required, VDB Entry
- https://vuldb.com/?submit.331995Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4731?
How severe is CVE-2024-4731?
How do I fix CVE-2024-4731?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-47304Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2024-47305Cross-Site Request Forgery (CSRF) vulnerability in Dnesscark…8.8
- CVE-2024-47306Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2024-47307Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-47308Missing Authorization vulnerability in WPDeveloper Templatel…9.8
- CVE-2024-47309Improper Limitation of a Pathname to a Restricted Directory …6.6
- CVE-2024-47310Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-47311Missing Authorization vulnerability in Kraft Plugins Wheel o…9.8
- CVE-2024-47312Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2024-47313Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2024-47314Missing Authorization vulnerability in sunshinephotocart Sun…8.8
- CVE-2024-47315Cross-Site Request Forgery (CSRF) vulnerability in StellarWP…8.8
Are you affected by CVE-2024-4731?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
