Description
Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects 2ClickPortal software versions from 7.2.31 through 7.6.4.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47085 | Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects 2ClickPortal software versions from 7.2.31 through 7.6.4. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-08-01T21:25:03.175Z
Reserved: 2024-06-13T10:10:32.570Z
Link: CVE-2024-5961
Updated: 2024-08-01T21:25:03.175Z
Status : Deferred
Published: 2024-06-14T08:15:42.377
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-5961
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD