{ "id": "CVE-2024-28741", "sourceIdentifier": "cve@mitre.org", "published": "2024-04-06T19:15:07.247", "lastModified": "2024-04-08T18:48:40.217", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component." }, { "lang": "es", "value": "Vulnerabilidad de cross-site scripting en EginDemirbilek NorthStar C2 v1 permite a un atacante remoto ejecutar c\u00f3digo arbitrario a trav\u00e9s del componente login.php." } ], "metrics": {}, "references": [ { "url": "https://blog.chebuya.com/posts/discovering-cve-2024-28741-remote-code-execution-on-northstar-c2-agents-via-pre-auth-stored-xss/", "source": "cve@mitre.org" }, { "url": "https://github.com/EnginDemirbilek/NorthStarC2", "source": "cve@mitre.org" }, { "url": "https://packetstormsecurity.com/files/177542/NorthStar-C2-Agent-1.0-Cross-Site-Scripting-Remote-Command-Execution.html", "source": "cve@mitre.org" } ] }