cvelist/2024/24xxx/CVE-2024-24336.json

62 lines
2.0 KiB
JSON
Raw Normal View History

2024-01-25 10:00:49 +00:00
{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
2024-04-01 20:50:31 +00:00
"ID": "CVE-2024-24336",
"STATE": "PUBLIC"
2024-01-25 10:00:49 +00:00
},
2024-04-01 20:50:31 +00:00
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2024-01-25 10:00:49 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2024-04-01 20:50:31 +00:00
"value": "A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and \u2018/members/members-home.pl\u2019 endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized changes to usernames and passwords of users visiting the affected page, via the 'Circulation note' and \u2018Patrons Restriction\u2019 components."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://nitipoom-jar.github.io/CVE-2024-24336/",
"url": "https://nitipoom-jar.github.io/CVE-2024-24336/"
2024-01-25 10:00:49 +00:00
}
]
}
}