CVE-2024-40347: XSS
A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter htmlid.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40347?
CVE-2024-40347 is classified as a reflected cross-site scripting (XSS) vulnerability, which can lead to arbitrary code execution in the user's browser.
How do I fix CVE-2024-40347?
To fix CVE-2024-40347, update the Hyland Alfresco Platform to a version higher than 23.2.1-r96, ensuring you implement security best practices for input validation.
What versions of Hyland Alfresco are affected by CVE-2024-40347?
CVE-2024-40347 affects Hyland Alfresco Platform versions up to 23.2.1-r96 but is fixed in later releases.
What type of attack does CVE-2024-40347 enable?
CVE-2024-40347 enables attackers to perform reflected XSS attacks by injecting malicious payloads through the htmlid parameter.
Who is vulnerable to CVE-2024-40347?
Users of Hyland Alfresco Platform prior to version 23.3 are vulnerable to CVE-2024-40347 and should take immediate action to mitigate this risk.