First published: Thu Apr 18 2024(Updated: )
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Derbynet | <=9.0 | |
Derbynet | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30927 has a medium severity rating due to its potential for cross-site scripting attacks that could allow arbitrary code execution.
To fix CVE-2024-30927, update Apache DerbyNet to version 9.1 or later to eliminate the vulnerability.
The racer-results.php component in DerbyNet versions 9.0 and below is affected by CVE-2024-30927.
Users of Apache DerbyNet version 9.0 and below are affected by CVE-2024-30927.
CVE-2024-30927 is classified as a cross-site scripting (XSS) vulnerability.