CVE-2024-2211: Cross-Site Scripting vulnerability in Gophish Admin Panel
Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the campaign is removed from the menu.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2211?
CVE-2024-2211 has been classified as a medium severity vulnerability due to its potential to execute malicious scripts within the Gophish application.
How do I fix CVE-2024-2211?
To mitigate CVE-2024-2211, upgrade Gophish to the latest version where the vulnerability has been addressed.
What versions are affected by CVE-2024-2211?
CVE-2024-2211 affects Gophish version 0.12.1.
What type of vulnerability is CVE-2024-2211?
CVE-2024-2211 is a Cross-Site Scripting (XSS) stored vulnerability allowing the injection of malicious JavaScript.
What can an attacker do with CVE-2024-2211?
An attacker can exploit CVE-2024-2211 to store a malicious payload that executes when a campaign is removed from the menu.