CVE-2024-9411

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://gitee.com/oufu/ofcms/issues/IATECW Broken Link
https://vuldb.com/?ctiid.278973 Permissions Required VDB Entry
https://vuldb.com/?id.278973 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:ofcms_project:ofcms:1.1.2:*:*:*:*:*:*:*

History

27 May 2025, 19:07

Type Values Removed Values Added
CPE cpe:2.3:a:ofcms_project:ofcms:1.1.2:*:*:*:*:*:*:*
First Time Ofcms Project
Ofcms Project ofcms
References () https://gitee.com/oufu/ofcms/issues/IATECW - () https://gitee.com/oufu/ofcms/issues/IATECW - Broken Link
References () https://vuldb.com/?ctiid.278973 - () https://vuldb.com/?ctiid.278973 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.278973 - () https://vuldb.com/?id.278973 - Third Party Advisory, VDB Entry

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como problemática en OFCMS 1.1.2. Afecta a la función add del archivo /admin/system/dict/add.json?sqlid=system.dict.save. La manipulación del argumento dict_value provoca ataques de Cross-Site Scripting. Es posible iniciar el ataque de forma remota. El exploit se ha hecho público y puede utilizarse.

01 Oct 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-01 20:15

Updated : 2025-05-27 19:07


NVD link : CVE-2024-9411

Mitre link : CVE-2024-9411

CVE.ORG link : CVE-2024-9411


JSON object : View

Products Affected

ofcms_project

  • ofcms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')