2024-07-29 16:03:14 +00:00

72 lines
2.8 KiB
JSON

{
"id": "CVE-2024-41805",
"sourceIdentifier": "security-advisories@github.com",
"published": "2024-07-26T15:15:11.327",
"lastModified": "2024-07-29T14:12:08.783",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious JavaScript in the context of a user\u2019s browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft. Tracks version 2.7.1 is patched. No known complete workarounds are available."
},
{
"lang": "es",
"value": "Tracks, una aplicaci\u00f3n web Getting Things Done (GTD), es vulnerable a Cross Site Scripting reflejado en versiones anteriores a la 2.7.1. El Cross Site Scripting reflejado permite la ejecuci\u00f3n de JavaScript malicioso en el contexto del navegador de un usuario si ese usuario hace clic en un enlace malicioso, lo que permite ataques de phishing que podr\u00edan conducir al robo de credenciales. La versi\u00f3n 2.7.1 de Tracks est\u00e1 parcheada. No se conocen soluciones completas disponibles."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/TracksApp/tracks/commit/b0d288d2efd0f8020d04ca95b8e0738a9eab6c51",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/TracksApp/tracks/commit/c23ca0574ec1149993476632ffd66643aec6aac2",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/TracksApp/tracks/releases/tag/v2.7.1",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/TracksApp/tracks/security/advisories/GHSA-fp4p-59hr-3695",
"source": "security-advisories@github.com"
}
]
}