Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-46240 - Vulnerability Database
Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-46240
Medium
Reference:
CVE-2024-46240
Title:
Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under actionsystem and the company/contact parameters under actionaddcust within admin.php file.