2024-11-18 19:03:31 +00:00

96 lines
2.9 KiB
JSON

{
"id": "CVE-2024-11021",
"sourceIdentifier": "twcert@cert.org.tw",
"published": "2024-11-11T08:15:04.987",
"lastModified": "2024-11-18T19:00:03.487",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser."
},
{
"lang": "es",
"value": "Webopac de Grand Vice Info presenta una vulnerabilidad de Cross-site Scripting almacenado. Los atacantes remotos con privilegios normales pueden inyectar c\u00f3digo JavaScript arbitrario en el servidor. Cuando los usuarios visitan la p\u00e1gina comprometida, el c\u00f3digo se ejecuta autom\u00e1ticamente en su navegador."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6",
"versionEndExcluding": "6.5.1",
"matchCriteriaId": "05F9B655-8FA4-48EC-A45C-2023F4C74AF9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7",
"versionEndExcluding": "7.2.3",
"matchCriteriaId": "A2179D8C-B827-4464-918B-5C74013AC527"
}
]
}
]
}
],
"references": [
{
"url": "https://www.twcert.org.tw/en/cp-139-8220-e75c2-2.html",
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-8219-f12d0-1.html",
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory"
]
}
]
}