CVE-2024-45920

A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in "Intrest" feature.
References
Link Resource
https://gist.github.com/ipxsec/10526db2cbfcb899a70dcb8f0ee53a99 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:solvait:solvait:24.4.2:*:*:*:*:*:*:*

History

10 Jul 2025, 15:38

Type Values Removed Values Added
References () https://gist.github.com/ipxsec/10526db2cbfcb899a70dcb8f0ee53a99 - () https://gist.github.com/ipxsec/10526db2cbfcb899a70dcb8f0ee53a99 - Exploit, Third Party Advisory
CPE cpe:2.3:a:solvait:solvait:24.4.2:*:*:*:*:*:*:*
First Time Solvait solvait
Solvait

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Cross-Site Scripting (XSS) Almacenado en Solvait 24.4.2 permite a atacantes remotos inyectar secuencias de comandos maliciosas en la aplicación. Este problema surge debido a una validación y desinfección de entradas insuficientes en la función "Intrest".

30 Sep 2024, 18:35

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

30 Sep 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-30 13:15

Updated : 2025-07-10 15:38


NVD link : CVE-2024-45920

Mitre link : CVE-2024-45920

CVE.ORG link : CVE-2024-45920


JSON object : View

Products Affected

solvait

  • solvait
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')