CVE-2024-52763: XSS
A cross-site scripting (XSS) vulnerability in the component /graphallperiods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "g" parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52763?
CVE-2024-52763 is categorized as a cross-site scripting (XSS) vulnerability which can have a high severity depending on the attack vector.
How do I fix CVE-2024-52763?
To mitigate CVE-2024-52763, update Ganglia-web to version 3.7.6 or later, where the vulnerability is addressed.
What components are affected by CVE-2024-52763?
CVE-2024-52763 affects the /graph_all_periods.php component of Ganglia-web versions 3.73 to 3.75.
What type of attacks can CVE-2024-52763 enable?
CVE-2024-52763 allows attackers to execute arbitrary web scripts or HTML through crafted payloads.
Is user input involved in CVE-2024-52763?
Yes, the vulnerability is exploited via a crafted payload injected into the "g" parameter.