CVE-2024-51379
Last modified
CVE-2024-51379 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jatos | Jatos | 3.9.3 |
References
- https://hacking-notes.medium.com/cve-2024-51379-jatos-v3-9-3-stored-xss-description-component-de49d0077a96Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-51379?
How severe is CVE-2024-51379?
How do I fix CVE-2024-51379?
Are you affected by CVE-2024-51379?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
