elaine.com
http://elaine.com/ CVE-2024-42831
MEDIUM
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
Record summary
CVE-2024-42831 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 7, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
marketing_automationBrowse elaine / marketing_automationDefault status: unknown | CVE List | 6.18.17 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBElaine's Realtime CRM Automation 6.18.17 - Reflected XSSExploitDB exploitby arfaoui haythemNot analyzed1 file
References
5realtime.com
http://realtime.com/ seclists.org
http://seclists.org/fulldisclosure/2024/Sep/49 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42831 seclists.org
https://seclists.org/fulldisclosure/2024/Sep/49