Lucene search

K
vulnrichmentAppleVULNRICHMENT:CVE-2024-27794
HistoryApr 15, 2024 - 10:16 p.m.

CVE-2024-27794

2024-04-1522:16:30
apple
github.com
2
claris filemaker server
cross-site scripting
version 20.3.2
vulnerability
html escaping

AI Score

6.2

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*"
    ],
    "vendor": "claris",
    "product": "filemaker_server",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.2

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-27794