CVE-2009-2733

EUVD-2009-2724
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
achievoachievo
𝑥
≤ 1.3.4
achievoachievo
0.7.0
achievoachievo
0.7.1
achievoachievo
0.7.2
achievoachievo
0.7.3
achievoachievo
0.8.0
achievoachievo
0.8.0_rc1:_rc1
achievoachievo
0.8.0_rc2:_rc2
achievoachievo
0.8.1
achievoachievo
0.9.0
achievoachievo
0.9.1
achievoachievo
1.0.0
achievoachievo
1.0.0:rc1
achievoachievo
1.0.0:rc2
achievoachievo
1.0.0:rc3
achievoachievo
1.0.1
achievoachievo
1.0.2
achievoachievo
1.0.3
achievoachievo
1.0.4
achievoachievo
1.1.0
achievoachievo
1.1.0:rc1
achievoachievo
1.1.0:rc2
achievoachievo
1.1.0:rc3
achievoachievo
1.2.0
achievoachievo
1.2.0:rc1
achievoachievo
1.2.1
achievoachievo
1.3.0
achievoachievo
1.3.0:rc1
achievoachievo
1.3.0:rc2
achievoachievo
1.3.1
achievoachievo
1.3.2
achievoachievo
1.3.3
𝑥
= Vulnerable software versions