CVE-2024-29273: XSS
Published Mar 22, 2024
·Updated
There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.
Affected Software
2 affected components
dzzoffice DzzOffice
dzzoffice DzzOffice=2.02.1_sc_utf8
Event History
Mar 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29273?
CVE-2024-29273 is classified as a high severity Stored Cross-Site Scripting vulnerability.
2
How do I fix CVE-2024-29273?
To fix CVE-2024-29273, ensure proper input validation and sanitization for file uploads in dzzoffice.
3
What software is affected by CVE-2024-29273?
CVE-2024-29273 affects dzzoffice version 2.02.1 and possibly earlier versions utilizing the uploadfile functionality.
4
What does CVE-2024-29273 exploit?
CVE-2024-29273 exploits the upload functionality to allow attackers to inject and execute malicious scripts through SVG documents.
5
Can I safely use dzzoffice without addressing CVE-2024-29273?
Using dzzoffice without addressing CVE-2024-29273 poses a significant risk of attacks leveraging Stored XSS.