← Back

CVE-2024-25873

nvd nist
Published: Feb 22, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

Affected (1)

Products: Enhavo: Enhavo
1 product
Enhavo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.13.1

References (4)

Timeline

No history available yet.