First published: Tue May 21 2024(Updated: )
An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user input without sanitization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Italtel Embrace | =1.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31847 is classified as a stored cross-site scripting (XSS) vulnerability, which can potentially lead to significant security risks.
To fix CVE-2024-31847, ensure that all user input in GET parameters is properly validated and sanitized before being processed.
CVE-2024-31847 affects users and administrators of Italtel Embrace version 1.6.4.
Yes, CVE-2024-31847 can be exploited by both authenticated and unauthenticated remote attackers.
CVE-2024-31847 is associated with stored cross-site scripting (XSS) attacks, allowing injection of arbitrary scripts into web applications.