CVE-2024-24275: XSS
Published Mar 5, 2024
·Updated
Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.
Affected Software
3 affected components
Teamwire Windows desktop client>=2.0.1<=2.4.0
All of the following
Teamwire Teamwire>=2.0.1<2.4.0
Microsoft Windows
Event History
Mar 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24275?
CVE-2024-24275 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2024-24275?
To fix CVE-2024-24275, upgrade your Teamwire Windows desktop client to version 2.4.1 or later.
3
What products are affected by CVE-2024-24275?
CVE-2024-24275 affects Teamwire Windows desktop client versions 2.0.1 through 2.4.0.
4
What type of vulnerability is CVE-2024-24275?
CVE-2024-24275 is a Cross Site Scripting (XSS) vulnerability.
5
Can CVE-2024-24275 lead to data breaches?
Yes, CVE-2024-24275 can potentially lead to data breaches by allowing attackers to obtain sensitive information.