CVE-2024-47793: XSS
Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When accessing the edit screen containing custom columns (column type: images or files), an arbitrary script may be executed on the web browser of the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47793?
CVE-2024-47793 is classified as a high severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2024-47793?
To fix CVE-2024-47793, upgrade Exment to version 6.1.5 or 5.0.12, which address this vulnerability.
Which versions of Exment are affected by CVE-2024-47793?
CVE-2024-47793 affects Exment versions 6.1.4 and earlier, and versions 5.0.11 and earlier.
What type of vulnerability is CVE-2024-47793?
CVE-2024-47793 is a stored cross-site scripting vulnerability that can execute arbitrary scripts in user browsers.
Where does CVE-2024-47793 occur in the Exment application?
CVE-2024-47793 occurs on the edit screen when handling custom columns of type images or files.