CVE-2024-37623: XSS
Published Jun 17, 2024
·Updated
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tplkaoqinlocationchange.html component.
Affected Software
2 affected components
Xinhu RockOA
Rockoa Xinhu=2.6.3
Event History
Jun 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37623?
CVE-2024-37623 has been classified as a medium severity vulnerability due to the potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-37623?
To fix CVE-2024-37623, you should update Xinhu RockOA to the latest version that addresses this reflected XSS vulnerability.
3
What component of Xinhu RockOA is affected by CVE-2024-37623?
CVE-2024-37623 affects the /kaoqin/tpl_kaoqin_locationchange.html component of Xinhu RockOA v2.6.3.
4
What type of vulnerability is CVE-2024-37623?
CVE-2024-37623 is a reflected cross-site scripting (XSS) vulnerability.
5
Who is the vendor responsible for CVE-2024-37623?
The vendor responsible for CVE-2024-37623 is Xinhu.