CVE-2024-1257: Jspxcms find_text.do cross site scripting
Published Feb 6, 2024
·Updated
A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252996.
Affected Software
1 affected component
Ujcms Jspxcms=10.2.0
Event History
Feb 6, 2024
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-1257?
CVE-2024-1257 has been classified as problematic due to the potential for cross site scripting attacks.
2
How do I fix CVE-2024-1257?
To fix CVE-2024-1257, it is advised to update Jspxcms to a patched version that addresses this vulnerability.
3
What software is affected by CVE-2024-1257?
CVE-2024-1257 affects Jspxcms version 10.2.0.
4
What type of vulnerability is CVE-2024-1257?
CVE-2024-1257 is a cross site scripting (XSS) vulnerability.
5
Can CVE-2024-1257 be exploited remotely?
Yes, CVE-2024-1257 can be exploited remotely.