Description
Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.php, settings_invoice.php, settings_localization.php, settings_mail.php components.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 25 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Itflow
Itflow itflow |
|
| CPEs | cpe:2.3:a:itflow:itflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Itflow
Itflow itflow |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T18:25:20.180Z
Reserved: 2024-02-07T00:00:00.000Z
Link: CVE-2024-25344
Updated: 2024-08-01T23:44:08.463Z
Status : Analyzed
Published: 2024-02-26T16:27:58.897
Modified: 2025-04-25T19:04:02.670
Link: CVE-2024-25344
No data.
OpenCVE Enrichment
No data.
Weaknesses