CVE-2024-48392

OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.
Configurations

Configuration 1 (hide)

cpe:2.3:a:orangescrum:orangescrum:2.0.11:*:*:*:*:*:*:*

History

30 Sep 2025, 21:01

Type Values Removed Values Added
References () https://github.com/Renzusclarke/CVE-2024-48392-PoC - () https://github.com/Renzusclarke/CVE-2024-48392-PoC - Exploit
References () https://github.com/Renzusclarke/CVE-2024-48392-PoC/blob/main/poc.txt - () https://github.com/Renzusclarke/CVE-2024-48392-PoC/blob/main/poc.txt - Exploit
References () https://www.orangescrum.com/ - () https://www.orangescrum.com/ - Product
CPE cpe:2.3:a:orangescrum:orangescrum:2.0.11:*:*:*:*:*:*:*
First Time Orangescrum orangescrum
Orangescrum

22 Jan 2025, 22:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) OrangeScrum v2.0.11 es vulnerable a Cross Site Scripting (XSS). Un atacante puede inyectar código JavaScript malicioso en el correo electrónico del usuario debido a la falta de validación de entrada, lo que podría provocar el robo de la cuenta.
References () https://github.com/Renzusclarke/CVE-2024-48392-PoC/blob/main/poc.txt - () https://github.com/Renzusclarke/CVE-2024-48392-PoC/blob/main/poc.txt -

21 Jan 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 21:15

Updated : 2025-09-30 21:01


NVD link : CVE-2024-48392

Mitre link : CVE-2024-48392

CVE.ORG link : CVE-2024-48392


JSON object : View

Products Affected

orangescrum

  • orangescrum
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')