CVE-2024-54795: XSS
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54795?
CVE-2024-54795 is classified as a high severity vulnerability due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2024-54795?
To mitigate CVE-2024-54795, users should update SpagoBI to a patched version that addresses the stored XSS vulnerabilities.
What are the consequences of CVE-2024-54795?
Exploitation of CVE-2024-54795 can lead to unauthorized access to user session data and potential data exfiltration.
Who is affected by CVE-2024-54795?
CVE-2024-54795 affects users of SpagoBI version 3.5.1 who utilize the worksheet designer function.
What are stored cross-site scripting vulnerabilities in CVE-2024-54795?
Stored cross-site scripting vulnerabilities in CVE-2024-54795 allow attackers to inject malicious scripts that are stored on the server and executed when users access the affected application.