CVE-2024-25344: XSS
Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settingsdefaults.php,settingsintegrations.php, settingsinvoice.php, settingslocalization.php, settingsmail.php components.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25344?
CVE-2024-25344 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-25344?
To fix CVE-2024-25344, update your ITFlow application to the version after commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378.
Who is affected by CVE-2024-25344?
CVE-2024-25344 affects ITFlow.org installations prior to commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378.
What can attackers achieve with CVE-2024-25344?
Attackers exploiting CVE-2024-25344 can execute arbitrary code and access sensitive information.
When was CVE-2024-25344 reported?
CVE-2024-25344 was reported upon the discovery of vulnerabilities in versions prior to v.432488eca3998c5be6b6b9e8f8ba01f54bc12378.