Record summary

CVE-2025-24344 has a selected CVSS score of 6.3 (medium).

Description

A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, possibly, execute arbitrary client-side code in the context of another user's browser via a crafted HTTP request.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.12.0 to ≤ 1.12.1affected
1.20.0 to ≤ 1.20.1affected
2.6.0 to ≤ 2.6.0affected

References

2