CVE-2024-26542
EUVD-2024-2380727.02.2024, 22:15
Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload to the Groups Display name field.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bonitasoft | bonita_web | - |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| bonitasoft | bonita_web | 7.14 ≤ 𝑥 < 9.0.2 | ADP |
| bonitasoft | bonita_web | 7.14 ≤ 𝑥 < 8.0.3 | ADP |
| bonitasoft | bonita_web | 7.14 ≤ 𝑥 < 7.15.7 | ADP |
| bonitasoft | bonita_web | 7.14 ≤ 𝑥 < 7.14.8 | ADP |