CVE-2024-23349

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack. Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*

History

11 Dec 2024, 14:22

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/22/2 - () http://www.openwall.com/lists/oss-security/2024/02/22/2 - Mailing List, Third Party Advisory
References () https://lists.apache.org/thread/y5902t09vfgy7892z3vzr1zq900sgyqg - () https://lists.apache.org/thread/y5902t09vfgy7892z3vzr1zq900sgyqg - Mailing List, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Apache answer
Apache
CPE cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*

21 Nov 2024, 08:57

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/22/2 - () http://www.openwall.com/lists/oss-security/2024/02/22/2 -
References () https://lists.apache.org/thread/y5902t09vfgy7892z3vzr1zq900sgyqg - () https://lists.apache.org/thread/y5902t09vfgy7892z3vzr1zq900sgyqg -

22 Feb 2024, 16:15

Type Values Removed Values Added
Summary
  • (es) Neutralización inadecuada de la entrada durante la vulnerabilidad de generación de páginas web ('cross-site Scripting') en Apache Answer. Este problema afecta a Apache Answer: hasta 1.2.1. Ataque XSS cuando el usuario ingresa un resumen. Un usuario que haya iniciado sesión, al modificar su propia pregunta enviada, puede ingresar código malicioso en el resumen para crear dicho ataque. Se recomienda a los usuarios actualizar a la versión [1.2.5], que soluciona el problema.
References
  • () http://www.openwall.com/lists/oss-security/2024/02/22/2 -

22 Feb 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 10:15

Updated : 2025-03-28 20:15


NVD link : CVE-2024-23349

Mitre link : CVE-2024-23349

CVE.ORG link : CVE-2024-23349


JSON object : View

Products Affected

apache

  • answer
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')