https://seclists.org/oss-sec/2024/q1/153: CVE-2024-23349: Apache Answer: XSS vulnerability when submitting summary
Published Feb 22, 2024
·Updated
Affected Software
1 affected component
Apache Answer<=1.2.1
Frequently Asked Questions
1
What is the severity of CVE-2024-23349?
The severity of CVE-2024-23349 is classified as important.
2
Which versions of Apache Answer are affected by CVE-2024-23349?
CVE-2024-23349 affects Apache Answer versions through 1.2.1.
3
What is the primary issue caused by CVE-2024-23349?
CVE-2024-23349 is a Cross-site Scripting (XSS) vulnerability that occurs when a user submits a summary.
4
How can organizations mitigate CVE-2024-23349?
Organizations can mitigate CVE-2024-23349 by upgrading to a patched version of Apache Answer beyond 1.2.1.
5
What type of attack is possible due to CVE-2024-23349?
CVE-2024-23349 allows for XSS attacks that can be executed by logged-in users.