{ "id": "CVE-2024-24336", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-19T21:15:07.667", "lastModified": "2024-11-21T08:59:12.433", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and \u2018/members/members-home.pl\u2019 endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized changes to usernames and passwords of users visiting the affected page, via the 'Circulation note' and \u2018Patrons Restriction\u2019 components." }, { "lang": "es", "value": "Una vulnerabilidad de Cross-Site Scripting (XSS) m\u00faltiple en los endpoints '/members/moremember.pl' y '/members/members-home.pl' dentro de Koha Library Management System versi\u00f3n 23.05.05 y anteriores permite que usuarios malintencionados del personal lleven realizar ataques CSRF, incluidos cambios no autorizados en los nombres de usuario y contrase\u00f1as de los usuarios que visitan la p\u00e1gina afectada, a trav\u00e9s de los componentes 'Nota de circulaci\u00f3n' y 'Restricci\u00f3n de usuarios'." } ], "metrics": { "cvssMetricV31": [ { "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", "baseScore": 8.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" }, "exploitabilityScore": 2.8, "impactScore": 5.2 } ] }, "weaknesses": [ { "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-352" } ] } ], "references": [ { "url": "https://nitipoom-jar.github.io/CVE-2024-24336/", "source": "cve@mitre.org" }, { "url": "https://nitipoom-jar.github.io/CVE-2024-24336/", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }