CVE-2024-7790: DevikaAI Stored Cross-Site Scripting
Published Aug 14, 2024
·Updated
A stored cross site scripting vulnerabilities exists in DevikaAI from commit 6acce21fb08c3d1123ef05df6a33912bf0ee77c2 onwards via improperly decoded user input.
Affected Software
1 affected component
stitionai devika>=2024-06-08
Event History
Aug 14, 2024
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
DescriptionSeverity
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-7790?
CVE-2024-7790 is classified as a high severity vulnerability due to its potential to allow stored cross site scripting attacks.
2
How do I fix CVE-2024-7790?
To remediate CVE-2024-7790, ensure that user input is properly encoded and sanitized before rendering on the web page.
3
Which versions of DevikaAI are affected by CVE-2024-7790?
CVE-2024-7790 affects DevikaAI from version 2024-06-08 onward.
4
What type of vulnerability is CVE-2024-7790?
CVE-2024-7790 is a stored cross site scripting vulnerability.
5
Who is the vendor for the affected software in CVE-2024-7790?
The vendor for the affected software in CVE-2024-7790 is StitionAI.