CVE-2024-9411
Last modified
CVE-2024-9411 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ofcms Project | Ofcms | 1.1.2 |
References
- https://gitee.com/oufu/ofcms/issues/IATECWBroken Link
- https://vuldb.com/?ctiid.278973Permissions Required, VDB Entry
- https://vuldb.com/?id.278973Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-9411?
How severe is CVE-2024-9411?
How do I fix CVE-2024-9411?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-9404This vulnerability could lead to denial-of-service or servic…8.7
- CVE-2024-9405An incorrect limitation of a path to a restricted directory …5.3
- CVE-2024-9407A vulnerability exists in the bind-propagation option of the…4.7
- CVE-2024-9408In Eclipse GlassFish since version 6.2.5 it is possible to p…9.8
- CVE-2024-9409CWE-400: An Uncontrolled Resource Consumption vulnerability …7.5
- CVE-2024-9410Ada.cx's Sentry configuration allowed for blind server-side …5.3
- CVE-2024-9412An improper authorization vulnerability exists in the Rockwe…8.4
- CVE-2024-9413The transport_message_handler function in SCP-Firmware relea…8
- CVE-2024-9414In LAquis SCADA version 4.7.1.511, a cross-site scripting vu…7
- CVE-2024-9415A Path Traversal vulnerability exists in the file upload fun…8.8
- CVE-2024-9416The Modula Image Gallery plugin for WordPress is vulnerable …5.4
- CVE-2024-9417The Hash Form – Drag & Drop Form Builder plugin for WordPres…6.1
Are you affected by CVE-2024-9411?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
