CVE-2024-23735: XSS
Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23735?
CVE-2024-23735 has a high severity level due to its potential for Cross Site Scripting (XSS) attacks that can compromise user data.
How do I fix CVE-2024-23735?
To mitigate CVE-2024-23735, upgrade the S/Notify application to version 4.0.0 or later.
Who is affected by CVE-2024-23735?
CVE-2024-23735 affects users of Savignano S/Notify before version 4.0.0 and potentially users of Atlassian Confluence using this product.
What type of vulnerability is CVE-2024-23735?
CVE-2024-23735 is a Cross Site Scripting (XSS) vulnerability related to the S/MIME certificate upload functionality in user profiles.
What can attackers exploit with CVE-2024-23735?
Attackers can exploit CVE-2024-23735 to manipulate user data through specially crafted certificates during the upload process.