CVE-2024-41640

MEDIUM

AML Surety Eco <3.5 - XSS

Title source: llm
STIX 2.1

Description

Cross Site Scripting (XSS) vulnerability in AML Surety Eco up to 3.5 allows an attacker to run arbitrary code via crafted GET request using the id parameter.

Exploits (1)

nomisec WRITEUP
by alemusix · poc
https://github.com/alemusix/CVE-2024-41640

Scores

CVSS v3 6.1
EPSS 0.0100
EPSS Percentile 77.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Jul 29, 2024
Tracked Since Feb 18, 2026