Home

Description

Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects DInGO dLibra software in versions from 6.0 before 6.3.20.

PUBLISHED Reserved 2024-07-26 | Published 2024-11-14 | Updated 2024-11-14 | Assigner CERT-PL




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/AU:Y/R:A/U:Green

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

6.0 (custom) before 6.3.20
affected

Credits

Kacper Rybczyński finder

References

cert.pl/en/posts/2024/11/CVE-2024-7124/ third-party-advisory

cert.pl/posts/2024/11/CVE-2024-7124/ third-party-advisory

dingo.psnc.pl/dlibra/ product

cve.org (CVE-2024-7124)

nvd.nist.gov (CVE-2024-7124)

Download JSON