Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10089

Опубликовано: 14 апр. 2025
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for changing user's data with a malicious script, what causes the script to run in user's context.  This vulnerability has been patched in version 79.0

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:softcom.wroc:iksoris:*:*:*:*:*:*:*:*
Версия до 79.0 (исключая)

EPSS

Процентиль: 13%
0.00042
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
10 месяцев назад

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for changing user's data with a malicious script, what causes the script to run in user's context.  This vulnerability has been patched in version 79.0

EPSS

Процентиль: 13%
0.00042
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79