Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12796

Опубликовано: 16 сент. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT, Consultancy Coop. Workcube ERP allows Reflected XSS.This issue affects Workcube ERP: from V12 - V14 before Cognitive.

EPSS

Процентиль: 17%
0.00053
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.3
github
5 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT, Consultancy Coop. Workcube ERP allows Reflected XSS.This issue affects Workcube ERP: from V12 - V14 through 20250916.  NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.

EPSS

Процентиль: 17%
0.00053
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79