- Description
- A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
- Source
- cna@vuldb.com
- NVD status
- Analyzed
CVSS 4.0
- Type
- Secondary
- Base score
- 5.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Secondary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:N/I:P/A:N
- Hype score
- Not currently trending
CVE-2024-11971 Remote XSS Vulnerability in jpress 5.1.2 Avatar Handler A problematic vulnerability exists in Guizhou Xiaoma Technology jpress 5.1.2. It affects the /commons/attachment/upload file in the Avatar Ha... https://t.co/krjIBoCckI
@VulmonFeeds
29 Nov 2024
51 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE Alert: CVE-2024-11971 - https://t.co/kNG3RxIEPT #OSINT #ThreatIntel #CyberSecurity #cve_2024_11971
@RedPacketSec
29 Nov 2024
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-11971 A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file … https://t.co/r41R4WRv7K
@CVEnew
28 Nov 2024
520 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jpress:jpress:5.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D7771EC-8856-4D0E-8D12-D6BA66B75295"
}
],
"operator": "OR"
}
]
}
]