← Back

CVE-2024-31609

nvd nist
Published: Apr 25, 2024Modified: Apr 18, 2025

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.

Affected (1)

Products: Bosscms: Bosscms
1 product
Bosscms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.10.0

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.