CVE-2024-11479

MEDIUM

Issuetrak 17.1 - Authenticated HTML Injection in Ticket Comments

Title source: llm
STIX 2.1

Description

A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. HTML markup could be added to comments of tickets, which when submitted will render in the emails sent to all users on that ticket.

References (1)

Core 1

Scores

CVSS v4 5.1
EPSS 0.0037
EPSS Percentile 28.2%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-80
Status published
Products (1)
Issuetrak/Issuetrak Issuetrak 17.1
Published Dec 04, 2024
Tracked Since Feb 18, 2026