CVE-2024-42904
03.09.2024, 18:15
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientController.php.
Vendor | Product | Version |
---|---|---|
syspass | syspass | 3.2.0 ≤ 𝑥 ≤ 3.2.11 |
𝑥
= Vulnerable software versions