CVE-2024-45960
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.
Affected (1)
Products: Tribalsystems: Zenario
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.7.61188 |
References (1)
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.