CVE-2024-49505: XSS vulnerability found in OpenSuse MirrorCache
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters. This issue affects MirrorCache before 1.083.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49505?
CVE-2024-49505 is a high-severity vulnerability due to its potential for reflected cross-site scripting.
How do I fix CVE-2024-49505?
To fix CVE-2024-49505, upgrade to MirrorCache version 1.083 or later.
What affected software versions are impacted by CVE-2024-49505?
CVE-2024-49505 affects openSUSE MirrorCache versions before 1.083.
What is the nature of the vulnerability in CVE-2024-49505?
CVE-2024-49505 is an improper neutralization of input during web page generation, allowing for reflected cross-site scripting attacks.
Who is affected by CVE-2024-49505?
Users and administrators of openSUSE Tumbleweed running vulnerable versions of MirrorCache are affected by CVE-2024-49505.