First published: Wed Feb 28 2024(Updated: )
F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
=1.0 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25831 has a medium severity level due to the potential for arbitrary JavaScript execution affecting users of F-logic DataCube3 Version 1.0.
To fix CVE-2024-25831, ensure proper input sanitization is implemented in the web management interface of F-logic DataCube3 Version 1.0.
CVE-2024-25831 affects authenticated users of F-logic DataCube3 Version 1.0 who can interact with the web management interface.
CVE-2024-25831 is a reflected cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary code.
Yes, CVE-2024-25831 can be exploited remotely by authenticated attackers leveraging the XSS flaw.