First published: Thu Apr 18 2024(Updated: )
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Derbynet | <=9.0 | |
Derbynet | <9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30929 is considered a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2024-30929, upgrade DerbyNet to version 9.1 or higher where the vulnerability has been patched.
CVE-2024-30929 allows attackers to execute arbitrary code by exploiting a Cross Site Scripting vulnerability in the 'back' parameter.
CVE-2024-30929 affects DerbyNet version 9.0 and below.
CVE-2024-30929 is a server-side vulnerability that can affect how web applications process user input.