CVE-2024-5624: Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL
Published Aug 29, 2024
·Updated
Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session
Affected Software
1 affected component
Br-automation Industrial Automation Aprol<=r4.4-00p3
Event History
Aug 29, 2024
CVE Published
via MITRE·08:53 AM
Data Sourced
via MITRE·08:53 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5624?
CVE-2024-5624 has a severity level that indicates a significant risk due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-5624?
To fix CVE-2024-5624, update the B&R APROL application to a version later than R 4.4-00P3 that addresses this vulnerability.
3
Who is affected by CVE-2024-5624?
CVE-2024-5624 affects users of B&R APROL versions up to and including R 4.4-00P3.
4
What type of vulnerability is CVE-2024-5624?
CVE-2024-5624 is a reflected cross-site scripting (XSS) vulnerability.
5
What could an attacker achieve with CVE-2024-5624?
An attacker could execute arbitrary JavaScript code in the context of the user's browser session using CVE-2024-5624.