Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getflightpath
Getflightpath flightpath |
|
| CPEs | cpe:2.3:a:getflightpath:flightpath:7.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Getflightpath
Getflightpath flightpath |
Mon, 18 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 15 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-18T19:03:58.147Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-50983
Updated: 2024-11-18T19:03:43.355Z
Status : Analyzed
Published: 2024-11-15T22:15:15.907
Modified: 2025-07-07T16:12:47.073
Link: CVE-2024-50983
No data.
OpenCVE Enrichment
No data.