CVE-2024-34400: XSS
Published Jun 25, 2024
·Updated
An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS.
Affected Software
1 affected component
VirtoSoftware Virto Kanban Board Web Part<5.3.5.1
Event History
Jun 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-34400?
CVE-2024-34400 has a high severity due to its potential for cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2024-34400?
To fix CVE-2024-34400, upgrade to Virto Kanban Board Web Part version 5.3.5.1 or later.
3
What is the impact of CVE-2024-34400?
The impact of CVE-2024-34400 includes the ability for attackers to execute malicious scripts in users' browsers.
4
What versions are affected by CVE-2024-34400?
All versions of Virto Kanban Board Web Part prior to 5.3.5.1 are affected by CVE-2024-34400.
5
Is there a workaround for CVE-2024-34400 if I can't upgrade?
There are no known workarounds for CVE-2024-34400, and upgrading is the recommended solution.