CVE ID | CVE-2024-5961 |
Publication date | 14 June 2024 |
Vendor | Trol InterMedia Sp. z o.o. Sp. k. |
Product | 2ClickPortal |
Vulnerable versions | From 7.2.31 through 7.6.4 |
Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Trol InterMedia Sp. z o.o. Sp. k. 2ClickPortal software and participated in coordination of its disclosure.
The vulnerability CVE-2024-5961 allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects 2ClickPortal software versions from 7.2.31 through 7.6.4. Version 7.6.5 is unaffected. The update should be deployed automatically to all client systems.
Credits
We thank Kacper Rybczyński for the responsible vulnerability report. We thank also the vendor for the immediate remediation of the reported flaw.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.