CVE-2024-41504

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.
Configurations

No configuration.

History

11 Jun 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://github.com/rafaelbaldasso/CVE-2024-41504 - () https://github.com/rafaelbaldasso/CVE-2024-41504 -
CWE CWE-79
Summary
  • (es) Jetimob Plataforma Imobiliaria 20240627-0 es vulnerable a ataques de cross site scripting (XSS). En la sección "Oportunidades" de la aplicación, al crear o editar una "Actividad", el campo de formulario "Descripción" permite la inyección de JavaScript.

10 Jun 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 20:15

Updated : 2025-06-12 16:06


NVD link : CVE-2024-41504

Mitre link : CVE-2024-41504

CVE.ORG link : CVE-2024-41504


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')