CVE-2024-6369

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the file /labvantage/rc?command=page&sdcid=LV_ReagentLot of the component POST Request Handler. The manipulation of the argument mode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-269802 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:labvantage:laboratory_information_management_system:2017:*:*:*:*:*:*:*

History

17 Sep 2024, 19:19

Type Values Removed Values Added
First Time Labvantage laboratory Information Management System
Labvantage
Summary
  • (es) Una vulnerabilidad ha sido encontrada en LabVantage LIMS 2017 y clasificada como problemática. Una función desconocida del archivo /labvantage/rc?command=page&sdcid=LV_ReagentLot del componente POST Request Handler es afectada por esta vulnerabilidad. La manipulación del argumento mode conduce a Cross Site Scripting. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-269802 es el identificador asignado a esta vulnerabilidad.
References () https://gentle-khaan-c53.notion.site/Reflected-XSS-in-Labvantage-LIMS-960bf61d35124c858e3360785cfe40b3?pvs=4 - () https://gentle-khaan-c53.notion.site/Reflected-XSS-in-Labvantage-LIMS-960bf61d35124c858e3360785cfe40b3?pvs=4 - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.269802 - () https://vuldb.com/?ctiid.269802 - Permissions Required
References () https://vuldb.com/?id.269802 - () https://vuldb.com/?id.269802 - Third Party Advisory
References () https://vuldb.com/?submit.359373 - () https://vuldb.com/?submit.359373 - Third Party Advisory
CVSS v2 : 4.0
v3 : 3.5
v2 : 4.0
v3 : 5.4
CPE cpe:2.3:a:labvantage:laboratory_information_management_system:2017:*:*:*:*:*:*:*

27 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 12:15

Updated : 2024-09-17 19:19


NVD link : CVE-2024-6369

Mitre link : CVE-2024-6369

CVE.ORG link : CVE-2024-6369


JSON object : View

Products Affected

labvantage

  • laboratory_information_management_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')