CVE-2024-11348

Eura7 CMSmanager in version 4.6 and belowis vulnerable to Reflected XSS attacks through manipulation ofreturn GET request parameter sent to a specificendpoint.
The vulnerability has been fixed by a patchepatch 17012022 addressing all affected versions in use.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
CERT-PLCNA
---
---
CISA-ADPADP
---
---