Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.
References
Link | Resource |
---|---|
http://dcat-admin.com | Product |
https://github.com/jqhph/dcat-admin | Product |
https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m | Exploit Third Party Advisory |
http://dcat-admin.com | Product |
https://github.com/jqhph/dcat-admin | Product |
https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
30 Apr 2025, 16:48
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dcatadmin
Dcatadmin dcat Admin |
|
References | () http://dcat-admin.com - Product | |
References | () https://github.com/jqhph/dcat-admin - Product | |
References | () https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:dcatadmin:dcat_admin:2.0.19:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.3:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.17:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.11:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.5:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.1.1:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.9:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.23:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.14:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.4:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:*:*:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.1.0:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.16:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.1.2:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.20:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.1.3:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.12:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.7:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.0:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.18:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.2:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.15:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.22:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.6:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.24:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.13:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.10:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.8:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.1:beta:*:*:*:*:*:* cpe:2.3:a:dcatadmin:dcat_admin:2.0.21:beta:*:*:*:*:*:* |
24 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
21 Nov 2024, 09:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://dcat-admin.com - | |
References | () https://github.com/jqhph/dcat-admin - | |
References | () https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m - |
05 Aug 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
26 Mar 2024, 12:55
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-26 12:15
Updated : 2025-04-30 16:48
NVD link : CVE-2024-29644
Mitre link : CVE-2024-29644
CVE.ORG link : CVE-2024-29644
JSON object : View
Products Affected
dcatadmin
- dcat_admin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')