CVE-2024-37783: XSS
A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37783?
CVE-2024-37783 is classified as a reflected cross-site scripting (XSS) vulnerability, which can lead to malicious JavaScript being executed in a victim's browser.
How do I fix CVE-2024-37783?
To fix CVE-2024-37783, ensure that user input is properly sanitized and validate the sessionId parameter to prevent the injection of malicious scripts.
Who is affected by CVE-2024-37783?
CVE-2024-37783 affects users of Gladinet CentreStack version 13.12.9934.54690.
What type of attack does CVE-2024-37783 allow?
CVE-2024-37783 allows attackers to perform reflected cross-site scripting (XSS) attacks by injecting malicious JavaScript into the browser of a victim.
Where is the vulnerability in CVE-2024-37783 located?
The vulnerability in CVE-2024-37783 is located in the /portal/ForgotPassword.aspx page, specifically targeting the sessionId parameter.