Vulnerability Description
Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Monicahq | Monica | 4.1.2 |
Related Weaknesses (CWE)
References
- https://github.com/Allevon412/Monica-Stored-XSS-VulnerabilityExploitThird Party Advisory
FAQ
What is CVE-2024-54951?
CVE-2024-54951 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.
How severe is CVE-2024-54951?
CVE-2024-54951 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-54951?
Check the references section above for vendor advisories and patch information. Affected products include: Monicahq Monica.