CVE-2024-8411
LOWABCD ABCD2 <= 2.2.0-beta-1 - Cross-Site Scripting via Sub_Expresion Argument
Title source: llmDescription
A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The developer explains, that "this script has been completely redesigned after this version".
References (4)
Core 4
Core References
Permissions Required, Third Party Advisory vdb-entry
technical-description
https://vuldb.com/?id.276491
Permissions Required signature
permissions-required
https://vuldb.com/?ctiid.276491
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.398843
Scores
CVSS v3
3.5
EPSS
0.0049
EPSS Percentile
38.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
CWE-94
Status
published
Products (1)
abcd-community/abcd
2.2.0 alpha (2 CPE variants)
Published
Sep 04, 2024
Tracked Since
Feb 18, 2026