CVE-2024-6881: Stored XSS Vulnerability
Published Jul 29, 2024
·Updated
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
Affected Software
1 affected component
M-Files Hubshare<5.0.6.0
Remediation
Information
Update to patched version
Event History
Jul 29, 2024
CVE Published
via MITRE·12:56 PM
Data Sourced
via MITRE·12:56 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6881?
CVE-2024-6881 has a high severity rating due to its potential for execution of arbitrary JavaScript in users' browser sessions.
2
How do I fix CVE-2024-6881?
To fix CVE-2024-6881, upgrade to M-Files Hubshare version 5.0.6.0 or later.
3
Who is affected by CVE-2024-6881?
CVE-2024-6881 affects authenticated users of M-Files Hubshare versions prior to 5.0.6.0.
4
What type of vulnerability is CVE-2024-6881?
CVE-2024-6881 is classified as a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-6881 be exploited remotely?
CVE-2024-6881 requires authentication, meaning it can be exploited by users with access to the system.