CVE-2024-31847: XSS
An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user input without sanitization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31847?
CVE-2024-31847 is classified as a stored cross-site scripting (XSS) vulnerability, which can potentially lead to significant security risks.
How do I fix CVE-2024-31847?
To fix CVE-2024-31847, ensure that all user input in GET parameters is properly validated and sanitized before being processed.
Who is impacted by CVE-2024-31847?
CVE-2024-31847 affects users and administrators of Italtel Embrace version 1.6.4.
Can CVE-2024-31847 be exploited by unauthenticated users?
Yes, CVE-2024-31847 can be exploited by both authenticated and unauthenticated remote attackers.
What type of attack is CVE-2024-31847 associated with?
CVE-2024-31847 is associated with stored cross-site scripting (XSS) attacks, allowing injection of arbitrary scripts into web applications.