CVE-2024-29217

April 21, 2024, 4:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Apache Answer

  • before 1.3.0

Source

security@apache.org

Tags

CVE-2024-29217 details

Published : April 21, 2024, 4:15 p.m.
Last Modified : April 21, 2024, 4:15 p.m.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack. Users are recommended to upgrade to version [1.3.0], which fixes the issue.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description

References

URL Source
https://lists.apache.org/thread/nc0g1borr0d3wx25jm39pn7nyf268n0x security@apache.org
This website uses the NVD API, but is not approved or certified by it.