CVE ID | CVE-2024-11348 |
Publication date | 24 January 2025 |
Vendor | Eura7 |
Product | CMSmanager |
Vulnerable versions | All through 4.6 without patch 17012022 applied |
Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Eura7 CMSmanager software and participated in coordination of its disclosure.
Eura7 CMSmanager versions 4.6 and below are vulnerable to Reflected XSS attacks. This vulnerability can be exploited through manipulation of the return
GET request parameter sent to a specific endpoint. The vulnerability was assigned CVE-2024-11348.
The vulnerability has been fixed by a patch 17012022 addressing all affected versions in use (all below and including 4.6).
Credits
We thank Sebastian Jeż for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.