CVE-2024-4336 Information

Description

Adive Framework 2.0.8 does not sufficiently encode user-controlled inputs resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add in multiple parameters. An attacker could retrieve the session details of an authenticated user.

Reference

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-adive-framework

Share on: