CVE-2024-25344 Information
Feb 29, 2024
cve
Description
Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php settings+company.php settings_defaults.phpsettings_integrations.php settings_invoice.php settings_localization.php settings_mail.php components.
Reference
https://itflow.org/ https://github.com/itflow-org/itflow/commit/432488eca3998c5be6b6b9e8f8ba01f54bc12378 https://github.com/itflow-org/itflow/commit/8068cb6081e4760860a634c1066b2c64d0ee2d46 https://packetstormsecurity.com/files/177224/ITFlow-Cross-Site-Request-Forgery.html
Share on: