github.com
https://github.com/ayato-shitomi/CVE-2024-46278-teedy_1.11_account-takeover CVE-2024-46278
HIGH
Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
Record summary
CVE-2024-46278 has a selected CVSS score of 8.4 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 1.11 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBTeedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)ExploitDB exploitby Ayato Shitomi @ Fore-Z co.ltdNot analyzed1 file
Repository PoCs
GitHubayato-shitomi/CVE-2024-46278-teedy_1.11_account-takeoverRepository PoCby ayato-shitomiStars: 1Not analyzed2 files
References
3github.com
https://github.com/ayato-shitomi/teedy_1.11_account-takeover nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-46278