← back
CVE-2024-2727

Stored Cross-Site Scripting (Stored-XSS) vulnerability in the CIGESv2 system

CVSS 6.1 MEDIUMEPSS 0.3%CWE-79
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 Mar 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Ciges · CIGESv2