CVE-2024-6939: Xinhu RockOA tpl_upload.html okla cross site scripting
A vulnerability was found in Xinhu RockOA 2.6.3 and classified as problematic. Affected by this issue is the function okla of the file /webmain/public/upload/tplupload.html. The manipulation of the argument callback leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271994 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6939?
CVE-2024-6939 is classified as a problematic vulnerability with a potential risk of cross-site scripting.
How do I fix CVE-2024-6939?
To fix CVE-2024-6939, ensure proper input validation and sanitization of the callback argument in the affected function.
What systems are affected by CVE-2024-6939?
CVE-2024-6939 affects Xinhu RockOA version 2.6.3.
Can CVE-2024-6939 be exploited remotely?
Yes, CVE-2024-6939 can be exploited remotely through the manipulated callback argument.
What type of vulnerability is CVE-2024-6939?
CVE-2024-6939 is a cross-site scripting (XSS) vulnerability.