{ "id": "CVE-2024-46655", "sourceIdentifier": "cve@mitre.org", "published": "2024-09-25T18:15:05.297", "lastModified": "2024-09-25T18:15:05.297", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL." } ], "metrics": {}, "references": [ { "url": "https://csflabs.github.io/cve/2024/09/24/cve-2024-46655-Cross-Site-Scripting-%28XSS%29-%28Reflected%29-in-Ellevo-application.html", "source": "cve@mitre.org" }, { "url": "https://ellevo.com/", "source": "cve@mitre.org" } ] }