Lucene search

K
nvd[email protected]NVD:CVE-2024-5408
HistoryMay 27, 2024 - 1:15 p.m.

CVE-2024-5408

2024-05-2713:15:08
CWE-79
web.nvd.nist.gov
2
vulnerability
rhinos
remote attacker
user session
xss

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

AI Score

6.6

Confidence

High

EPSS

0

Percentile

9.0%

Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the “search” parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim’s user session by submitting a specially crafted URL.

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

AI Score

6.6

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2024-5408