CVE-2024-6892
Journyx Reflected Cross Site Scripting
Record summary
CVE-2024-6892 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Journyx (jtime)Browse Journyx / Journyx (jtime)Default status: unaffected | CVE List | 11.5.4 | affected |
journyxBrowse journyx / journyxDefault status: unknown | CVE List | 11.5.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMJournyx 11.5.4 - Reflected Cross Site ScriptingCVSS 6.1
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.
Impact
Attackers can craft malicious URLs with XSS payloads in the error_description parameter to execute arbitrary JavaScript when victims click the link.
Remediation
Update Journyx to version 11.5.5 or later to address the reflected XSS vulnerability.
Source: ProjectDiscovery