First published: Thu Apr 18 2024(Updated: )
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Derbynet | <9.0 | |
Derbynet | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-30925 is considered high due to its potential for executing arbitrary code.
To fix CVE-2024-30925, upgrade to a version of DerbyNet above 9.0 where the vulnerability has been addressed.
CVE-2024-30925 affects Apache DerbyNet version 9.0 and below.
CVE-2024-30925 is classified as a Cross Site Scripting (XSS) vulnerability.
Yes, CVE-2024-30925 can lead to data breaches as attackers can execute arbitrary code and potentially access sensitive information.