// For flags

CVE-2024-5961

Reflected XSS in 2ClickPortal

Severity Score

5.3
*CVSS v4

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects 2ClickPortal software versions from 7.2.31 through 7.6.4.

La neutralización inadecuada de la entrada durante la vulnerabilidad de generación de páginas web en el software 2ClickPortal permite cross-site scripting (XSS) reflejado. Un atacante podría engañar a alguien para que utilice una URL manipulada, lo que provocará que se ejecute un script en el navegador del usuario. Este problema afecta a las versiones del software 2ClickPortal desde la 7.2.31 hasta la 7.6.4.

*Credits: Kacper Rybczyński
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Passive
System
Vulnerable | Subsequent
Confidentiality
Low
Low
Integrity
Low
Low
Availability
Low
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-06-13 CVE Reserved
  • 2024-06-14 CVE Published
  • 2024-06-14 EPSS Updated
  • 2024-07-01 First Exploit
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
  • CAPEC-591: Reflected XSS
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Trol InterMedia Sp. Z O.o. Sp. K.
Search vendor "Trol InterMedia Sp. Z O.o. Sp. K."
2ClickPortal
Search vendor "Trol InterMedia Sp. Z O.o. Sp. K." for product "2ClickPortal"
>= 7.2.31 <= 7.6.4
Search vendor "Trol InterMedia Sp. Z O.o. Sp. K." for product "2ClickPortal" and version " >= 7.2.31 <= 7.6.4"
en
Affected