CVE-2024-6050
MEDIUMSOWA OPAC 4.0-4.9.9 and 5.0-6.2.11 - Reflected Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-6050. PoCs published by kac89.
AI-analyzed exploit summary This repository contains a proof-of-concept for a reflected XSS vulnerability in SOWA OPAC versions from 4.0 before 4.9.10 and from 5.0 before 6.2.12. The exploit leverages a vulnerable parameter in the URL to inject malicious JavaScript code.
Description
Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.
Exploits (1)
This repository contains a proof-of-concept for a reflected XSS vulnerability in SOWA OPAC versions from 4.0 before 4.9.10 and from 5.0 before 6.2.12. The exploit leverages a vulnerable parameter in the URL to inject malicious JavaScript code.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N