← volver
CVE-2024-2727

Stored Cross-Site Scripting (Stored-XSS) vulnerability in the CIGESv2 system

CVSS 6.1 MEDIUMEPSS 0.3%CWE-79
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
22 mar 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Productos afectados
Ciges · CIGESv2