Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44047 | The access control in CemiPark software does not properly validate user-entered data, which allows the stored cross-site scripting (XSS) attack. The parameters used to enter data into the system do not have appropriate validation, which makes possible to smuggle in HTML/JavaScript code. This code will be executed in the user's browser space.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products. |
Thu, 13 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-03-13T18:37:33.936Z
Reserved: 2024-05-02T11:55:32.039Z
Link: CVE-2024-4424
Updated: 2024-08-01T20:40:47.178Z
Status : Deferred
Published: 2024-05-14T15:43:41.587
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-4424
No data.
OpenCVE Enrichment
No data.
EUVD