Record summary

CVE-2024-52762 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 20, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMGanglia Web Interface (v3.7.3 - v3.7.6) - Cross-Site ScriptingCVSS 5.4

A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.

Impact

Authenticated attackers can execute arbitrary JavaScript or HTML in victim browsers by injecting malicious payloads into the tz parameter.

Remediation

Update Ganglia-web to version 3.7.7 or later to address the XSS vulnerability in the timezone parameter.

WeaknessesCWE-79
AuthorsDhiyaneshDk, daffainfo
Template tagscvecve2024gangliaxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ganglia:ganglia-web:*:*:*:*:*:*:*:*
Shodan: http.html:"ganglia_form.submit()"
FOFA: body="ganglia_form.submit()"

Source: ProjectDiscovery

References

2