Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre.
This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19450 | Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 10 Feb 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gallagher
Gallagher command Centre |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gallagher
Gallagher command Centre |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2024-08-01T22:27:36.320Z
Reserved: 2024-02-05T04:16:47.986Z
Link: CVE-2024-21838
Updated: 2024-08-01T22:27:36.320Z
Status : Analyzed
Published: 2024-03-05T03:15:06.280
Modified: 2025-02-10T22:33:35.600
Link: CVE-2024-21838
No data.
OpenCVE Enrichment
No data.
EUVD