Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-48707 - Vulnerability Database

Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-48707

Medium
Reference: CVE-2024-48707
Title: Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) actionadd or actionedit within managemilestone.php file and (b) actionaddpro within admin.php file.