Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.

Project Subscriptions

Vendors Products
Webopac Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-33611 Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
Fixes

Solution

Update Webopac 6 to version 6.5.1 or later. Update Webopac 7 to version 7.2.3 or later.


Workaround

No workaround given by the vendor.

History

Mon, 18 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Vice
Vice webopac
CPEs cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
Vendors & Products Vice
Vice webopac

Mon, 11 Nov 2024 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 Nov 2024 07:15:00 +0000

Type Values Removed Values Added
Description Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
Title Grand Vice info Webopac7 - Reflected XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-11-11T11:54:39.790Z

Reserved: 2024-11-08T05:54:43.466Z

Link: CVE-2024-11019

cve-icon Vulnrichment

Updated: 2024-11-11T11:54:26.049Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-11T07:15:05.517

Modified: 2024-11-18T18:59:24.527

Link: CVE-2024-11019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses