{ "id": "CVE-2024-25506", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-28T20:15:07.773", "lastModified": "2024-03-28T20:53:20.813", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie." }, { "lang": "es", "value": "Vulnerabilidad de cross-site scripting en Process Maker, Inc ProcessMaker anterior a 4.0 permite a un atacante remoto ejecutar c\u00f3digo arbitrario mediante el control de la cookie pm_sys_sys." } ], "metrics": {}, "references": [ { "url": "https://medium.com/%40proflamyt/cve-2024-25506-425ba3212fb6", "source": "cve@mitre.org" } ] }