CVE-2009-2733

Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
achievoachievo
𝑥
≤ 1.3.4
achievoachievo
0.7.0
achievoachievo
0.7.1
achievoachievo
0.7.2
achievoachievo
0.7.3
achievoachievo
0.8.0
achievoachievo
0.8.0_rc1:_rc1
achievoachievo
0.8.0_rc2:_rc2
achievoachievo
0.8.1
achievoachievo
0.9.0
achievoachievo
0.9.1
achievoachievo
1.0.0
achievoachievo
1.0.0:rc1
achievoachievo
1.0.0:rc2
achievoachievo
1.0.0:rc3
achievoachievo
1.0.1
achievoachievo
1.0.2
achievoachievo
1.0.3
achievoachievo
1.0.4
achievoachievo
1.1.0
achievoachievo
1.1.0:rc1
achievoachievo
1.1.0:rc2
achievoachievo
1.1.0:rc3
achievoachievo
1.2.0
achievoachievo
1.2.0:rc1
achievoachievo
1.2.1
achievoachievo
1.3.0
achievoachievo
1.3.0:rc1
achievoachievo
1.3.0:rc2
achievoachievo
1.3.1
achievoachievo
1.3.2
achievoachievo
1.3.3
𝑥
= Vulnerable software versions