CVE-2020-24902
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Quixplorer versiones anteriores a 2.4.1, es susceptible a una vulnerabilidad de tipo cross-site scripting (XSS) reflejado causado por una comprobación inapropiada de la entrada suministrada por el usuario. Un atacante remoto podría explotar esta vulnerabilidad usando una URL especialmente diseñada para ejecutar un script en el navegador Web de la víctima dentro del contexto de seguridad del sitio Web de hosting, una vez que la URL es cliqueada. Un atacante podría usar esta vulnerabilidad para robar las credenciales de autenticación basadas en las cookies de la víctima
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-28 CVE Reserved
- 2021-01-07 CVE Published
- 2024-01-11 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://dl.packetstormsecurity.net/1804-exploits/quixplorer241beta-xss.txt | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Quixplorer Project Search vendor "Quixplorer Project" | Quixplorer Search vendor "Quixplorer Project" for product "Quixplorer" | < 2.4.1 Search vendor "Quixplorer Project" for product "Quixplorer" and version " < 2.4.1" | - |
Affected
| ||||||
Quixplorer Project Search vendor "Quixplorer Project" | Quixplorer Search vendor "Quixplorer Project" for product "Quixplorer" | 2.4.1 Search vendor "Quixplorer Project" for product "Quixplorer" and version "2.4.1" | beta |
Affected
|