CVE-2024-46655

A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ellevo:ellevo:6.2.0.38160:*:*:*:*:*:*:*

History

02 Oct 2024, 15:40

Type Values Removed Values Added
References () https://csflabs.github.io/cve/2024/09/24/cve-2024-46655-Cross-Site-Scripting-%28XSS%29-%28Reflected%29-in-Ellevo-application.html - () https://csflabs.github.io/cve/2024/09/24/cve-2024-46655-Cross-Site-Scripting-%28XSS%29-%28Reflected%29-in-Ellevo-application.html - Exploit, Third Party Advisory
References () https://ellevo.com/ - () https://ellevo.com/ - Product
CPE cpe:2.3:a:ellevo:ellevo:6.2.0.38160:*:*:*:*:*:*:*
First Time Ellevo ellevo
Ellevo

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) reflejado en Ellevo 6.2.0.38160 permite a los atacantes ejecutar código arbitrario en el contexto del navegador de un usuario a través de un payload o URL manipulado específicamente.

25 Sep 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

25 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 18:15

Updated : 2024-10-02 15:40


NVD link : CVE-2024-46655

Mitre link : CVE-2024-46655

CVE.ORG link : CVE-2024-46655


JSON object : View

Products Affected

ellevo

  • ellevo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')