CVE-2024-4724: Campcodes Legal Case Management System case-type cross site scripting
A vulnerability, which was classified as problematic, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/case-type. The manipulation of the argument casetypename leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263802 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4724?
CVE-2024-4724 is classified as a problematic vulnerability affecting the Campcodes Legal Case Management System.
How does CVE-2024-4724 manifest in the software?
CVE-2024-4724 allows for cross-site scripting due to manipulation of the argument case_type_name in the /admin/case-type function.
What are the potential impacts of CVE-2024-4724?
Exploitation of CVE-2024-4724 can lead to unauthorized actions being executed in the context of the affected user's browser.
How do I fix CVE-2024-4724?
To mitigate CVE-2024-4724, sanitize and validate all user inputs related to the case_type_name argument.
Which version of the software is affected by CVE-2024-4724?
CVE-2024-4724 specifically affects version 1.0 of the Campcodes Legal Case Management System.