First published: Thu Feb 01 2024(Updated: )
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
aitangbao springboot-manager | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24062 has a high severity due to its potential to allow attackers to execute scripts in the context of the user's session.
To mitigate CVE-2024-24062, upgrade to a patched version of Springboot-manager that addresses the Cross Site Scripting vulnerability.
CVE-2024-24062 specifically affects Aitangbao Springboot-manager version 1.6.
CVE-2024-24062 is classified as a Cross Site Scripting (XSS) vulnerability.
CVE-2024-24062 can be exploited via the /sys/role endpoint in the affected application.