{ "id": "CVE-2024-25831", "sourceIdentifier": "cve@mitre.org", "published": "2024-02-29T01:44:16.630", "lastModified": "2024-02-29T13:49:29.390", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface." }, { "lang": "es", "value": "F-logic DataCube3 versi\u00f3n 1.0 se ve afectada por una vulnerabilidad de Cross-Site Scripting (XSS) reflejada debido a una sanitizaci\u00f3n de entrada inadecuada. Un atacante remoto autenticado puede ejecutar c\u00f3digo JavaScript arbitrario en la interfaz de administraci\u00f3n web." } ], "metrics": {}, "references": [ { "url": "https://neroteam.com/blog/f-logic-datacube3-vulnerability-report", "source": "cve@mitre.org" } ] }