Products
Apache Answer
- before 1.3.0
Source
security@apache.org
Tags
CVE-2024-29217 details
Published : April 21, 2024, 4:15 p.m.
Last Modified : April 21, 2024, 4:15 p.m.
Last Modified : April 21, 2024, 4:15 p.m.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack. Users are recommended to upgrade to version [1.3.0], which fixes the issue.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
https://lists.apache.org/thread/nc0g1borr0d3wx25jm39pn7nyf268n0x | security@apache.org |
This website uses the NVD API, but is not approved or certified by it.