CVE-2024-2692: SiYuan 3.0.3 - RCE via Server Side XSS
Published Apr 4, 2024
·Updated
SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.
Affected Software
2 affected components
SiYuan SiYuan
b3log SiYuan=3.0.3
Event History
Apr 4, 2024
CVE Published
via MITRE·01:26 AM
Data Sourced
via MITRE·01:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2692?
CVE-2024-2692 is classified as a critical vulnerability as it allows arbitrary command execution on the server.
2
How do I fix CVE-2024-2692?
To fix CVE-2024-2692, you should upgrade to the latest version of SiYuan that addresses this vulnerability.
3
What is the impact of CVE-2024-2692?
The impact of CVE-2024-2692 includes potential unauthorized access to the server and execution of malicious commands.
4
Which versions of SiYuan are affected by CVE-2024-2692?
CVE-2024-2692 affects SiYuan version 3.0.3.
5
Is CVE-2024-2692 a server-side vulnerability?
Yes, CVE-2024-2692 is a server-side vulnerability enabled by Server Side XSS.