Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Beian.Miit | Cool-Admin-Java | - |
Related Weaknesses (CWE)
References
- https://gist.github.com/kaoniniang2/05c2d0acdf8002b7121edff93d5230d6Third Party Advisory
- https://github.com/cool-team-official/cool-admin-javaProduct
- https://github.com/kaoniniang2/exploit/blob/main/Cool-admin-xss.mdExploitThird Party Advisory
- https://github.com/kaoniniang2/exploit/blob/main/Cool-admin-xss.mdExploitThird Party Advisory
FAQ
What is CVE-2024-57409?
CVE-2024-57409 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into th...
How severe is CVE-2024-57409?
CVE-2024-57409 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57409?
Check the references section above for vendor advisories and patch information. Affected products include: Beian.Miit Cool-Admin-Java.