CVE-2024-8411

LOW

ABCD ABCD2 <= 2.2.0-beta-1 - Cross-Site Scripting via Sub_Expresion Argument

Title source: llm
STIX 2.1

Description

A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The developer explains, that "this script has been completely redesigned after this version".

References (4)

Core 4
Core References
Permissions Required, Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.276491
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.276491
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.398843

Scores

CVSS v3 3.5
EPSS 0.0049
EPSS Percentile 38.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
abcd-community/abcd 2.2.0 alpha (2 CPE variants)
Published Sep 04, 2024
Tracked Since Feb 18, 2026