CVE-2024-50677
MEDIUMOroPlatform CMS 5.1 - Cross-Site Scripting via Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-50677. PoCs published by ZumiYumi.
AI-analyzed exploit summary This repository provides a detailed writeup and proof-of-concept for CVE-2024-50677, a two-click reflected XSS vulnerability in OroPlatform CMS v5.1. The vulnerability allows arbitrary JavaScript execution when a user interacts with a crafted search query.
Description
A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.
Exploits (1)
This repository provides a detailed writeup and proof-of-concept for CVE-2024-50677, a two-click reflected XSS vulnerability in OroPlatform CMS v5.1. The vulnerability allows arbitrary JavaScript execution when a user interacts with a crafted search query.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N