CVE-2024-4337 Information

Description

Adive Framework 2.0.8 does not sufficiently encode user-controlled inputs resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.

Reference

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-adive-framework

Share on: