CVE-2024-29644

Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dcatadmin:dcat_admin:*:*:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.1:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.2:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.3:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.4:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.5:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.6:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.7:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.8:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.9:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.10:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.11:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.12:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.13:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.14:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.15:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.16:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.17:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.18:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.19:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.20:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.21:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.22:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.23:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.24:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.0:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.1:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.2:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.3:beta:*:*:*:*:*:*

History

30 Apr 2025, 16:48

Type Values Removed Values Added
First Time Dcatadmin
Dcatadmin dcat Admin
References () http://dcat-admin.com - () http://dcat-admin.com - Product
References () https://github.com/jqhph/dcat-admin - () https://github.com/jqhph/dcat-admin - Product
References () https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m - () https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m - Exploit, Third Party Advisory
CPE cpe:2.3:a:dcatadmin:dcat_admin:2.0.19:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.3:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.17:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.11:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.5:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.1:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.9:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.23:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.14:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.4:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:*:*:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.0:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.16:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.2:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.20:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.1.3:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.12:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.7:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.18:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.2:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.15:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.22:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.6:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.24:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.13:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.10:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.8:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.1:beta:*:*:*:*:*:*
cpe:2.3:a:dcatadmin:dcat_admin:2.0.21:beta:*:*:*:*:*:*

24 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-79

21 Nov 2024, 09:08

Type Values Removed Values Added
References () http://dcat-admin.com - () http://dcat-admin.com -
References () https://github.com/jqhph/dcat-admin - () https://github.com/jqhph/dcat-admin -
References () https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m - () https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m -

05 Aug 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

26 Mar 2024, 12:55

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 12:15

Updated : 2025-04-30 16:48


NVD link : CVE-2024-29644

Mitre link : CVE-2024-29644

CVE.ORG link : CVE-2024-29644


JSON object : View

Products Affected

dcatadmin

  • dcat_admin
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')