THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-4754

Stored XSS in Next4Biz's BPM

Assigner:TR-CERT
Reserved:2024-05-10
Published:2024-06-24
Updated:2024-06-24

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.



MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

6.6.4.4 before 6.6.4.5
affected

Credits

Ertuğrul KUZGUN finder

References

https://www.usom.gov.tr/bildirim/tr-24-0739

cve.org CVE-2024-4754

nvd.nist.gov CVE-2024-4754

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-4754