Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-48708 - Vulnerability Database

Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-48708

Medium
Reference: CVE-2024-48708
Title: Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action add/edit and in (b) file admin.php under action adduser/edituser.