CVE-2024-27794: XSS
Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27794?
CVE-2024-27794 is considered a high severity vulnerability due to its potential impact on user data through reflected Cross-Site Scripting.
How do I fix CVE-2024-27794?
To fix CVE-2024-27794, upgrade to Claris FileMaker Server version 20.3.2 or later, which resolves the vulnerability.
What type of vulnerability is CVE-2024-27794?
CVE-2024-27794 is classified as a reflected Cross-Site Scripting (XSS) vulnerability.
Which versions of Claris FileMaker Server are affected by CVE-2024-27794?
CVE-2024-27794 affects all versions of Claris FileMaker Server prior to 20.3.2.
Is user data at risk due to CVE-2024-27794?
Yes, user data is at risk due to the potential execution of malicious scripts through the vulnerability.