CVE-2024-12020: Reflected Cross-Site Scripting (XSS)
There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the vulnerability. Stealing the session cookie is not possible due to cookie security flags, however the XSS may be used to induce a victim to perform on-site requests without their knowledge.
This vulnerability only affects LogicalDOC Enterprise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12020?
CVE-2024-12020 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-12020?
To fix CVE-2024-12020, ensure input validation and output encoding for user-generated content in JSP files.
What is the impact of CVE-2024-12020?
CVE-2024-12020 allows an unauthenticated attacker to execute malicious scripts in a user's browser.
Who is affected by CVE-2024-12020?
CVE-2024-12020 affects users of LogicalDOC Enterprise due to vulnerabilities in its JSP files.
Can CVE-2024-12020 lead to cookie theft?
No, CVE-2024-12020 does not allow cookie theft due to existing security flags on session cookies.