CVE-2024-23604

Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cleancoder:fitnesse:-:*:*:*:*:*:*:*

History

27 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:cleancoder:fitnesse:-:*:*:*:*:*:*:*
First Time Cleancoder fitnesse
Cleancoder
CWE CWE-79
References () http://fitnesse.org/FitNesseDownload - () http://fitnesse.org/FitNesseDownload - Product, Release Notes
References () https://github.com/unclebob/fitnesse - () https://github.com/unclebob/fitnesse - Product
References () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md - () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md - Product
References () https://jvn.jp/en/jp/JVN94521208/ - () https://jvn.jp/en/jp/JVN94521208/ - Third Party Advisory

21 Nov 2024, 08:57

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de cross-site scripting en todas las versiones de FitNesse, lo que puede permitir que un atacante remoto no autenticado ejecute un script arbitrario en el navegador web del usuario que utiliza el producto y accede a un enlace con múltiples parámetros especialmente manipulados.
References () http://fitnesse.org/FitNesseDownload - () http://fitnesse.org/FitNesseDownload -
References () https://github.com/unclebob/fitnesse - () https://github.com/unclebob/fitnesse -
References () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md - () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md -
References () https://jvn.jp/en/jp/JVN94521208/ - () https://jvn.jp/en/jp/JVN94521208/ -

18 Mar 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 08:15

Updated : 2025-03-27 20:15


NVD link : CVE-2024-23604

Mitre link : CVE-2024-23604

CVE.ORG link : CVE-2024-23604


JSON object : View

Products Affected

cleancoder

  • fitnesse
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')