CVE-2024-29644

Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
dcatadmindcat_admin
𝑥
≤ 1.7.9
dcatadmindcat_admin
2.0.0:beta
dcatadmindcat_admin
2.0.1:beta
dcatadmindcat_admin
2.0.2:beta
dcatadmindcat_admin
2.0.3:beta
dcatadmindcat_admin
2.0.4:beta
dcatadmindcat_admin
2.0.5:beta
dcatadmindcat_admin
2.0.6:beta
dcatadmindcat_admin
2.0.7:beta
dcatadmindcat_admin
2.0.8:beta
dcatadmindcat_admin
2.0.9:beta
dcatadmindcat_admin
2.0.10:beta
dcatadmindcat_admin
2.0.11:beta
dcatadmindcat_admin
2.0.12:beta
dcatadmindcat_admin
2.0.13:beta
dcatadmindcat_admin
2.0.14:beta
dcatadmindcat_admin
2.0.15:beta
dcatadmindcat_admin
2.0.16:beta
dcatadmindcat_admin
2.0.17:beta
dcatadmindcat_admin
2.0.18:beta
dcatadmindcat_admin
2.0.19:beta
dcatadmindcat_admin
2.0.20:beta
dcatadmindcat_admin
2.0.21:beta
dcatadmindcat_admin
2.0.22:beta
dcatadmindcat_admin
2.0.23:beta
dcatadmindcat_admin
2.0.24:beta
dcatadmindcat_admin
2.1.0:beta
dcatadmindcat_admin
2.1.1:beta
dcatadmindcat_admin
2.1.2:beta
dcatadmindcat_admin
2.1.3:beta
𝑥
= Vulnerable software versions