Record summary

CVE-2024-6892 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 9, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List11.5.4affected

Default status: unknown

CVE List11.5.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMJournyx 11.5.4 - Reflected Cross Site ScriptingCVSS 6.1

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

Impact

Attackers can craft malicious URLs with XSS payloads in the error_description parameter to execute arbitrary JavaScript when victims click the link.

Remediation

Update Journyx to version 11.5.5 or later to address the reflected XSS vulnerability.

WeaknessesCWE-81CWE-79
AuthorsDhiyaneshDk
Template tagscvecve2024xssjournyxseclistsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:journyx:journyx:11.5.4:*:*:*:*:*:*:*
Shodan: html:"Journyx"

Source: ProjectDiscovery

References

3