cve/2024/CVE-2024-25506.md
2025-09-29 21:09:30 +02:00

756 B

CVE-2024-25506

Description

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

POC

Reference

Github