First published: Tue Oct 01 2024(Updated: )
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Scriptcase | <9.10.023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46081 is classified as a Cross Site Scripting (XSS) vulnerability, which poses a high risk to affected systems.
To fix CVE-2024-46081, it is recommended to upgrade to Scriptcase version 9.10.024 or later, which addresses this vulnerability.
Authenticated users of Scriptcase versions 9.10.023 and earlier are affected by CVE-2024-46081.
CVE-2024-46081 allows for stored Cross Site Scripting (XSS) attacks via malicious payloads in the To-Do List feature.
The potential impacts of CVE-2024-46081 include unauthorized access to user data and session hijacking due to the exploitation of XSS vulnerabilities.