Description
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-26866 | Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data. |
References
History
Fri, 24 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sapplica
Sapplica sentrifugo |
|
| CPEs | cpe:2.3:a:sapplica:sentrifugo:3.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Sapplica
Sapplica sentrifugo |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-02T01:17:58.097Z
Reserved: 2024-03-21T10:29:38.102Z
Link: CVE-2024-29877
Updated: 2024-08-02T01:17:58.097Z
Status : Analyzed
Published: 2024-03-21T14:15:09.353
Modified: 2025-01-24T18:17:39.100
Link: CVE-2024-29877
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD