CVE-2024-45879

T

he file upload function in the "QWKalkulation" tool of baltic-it TOPqw Webportal v1.35.287.1 (fixed in version 1.35.291), in /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, is vulnerable to Cross-Site Scripting (XSS). To exploit the persistent XSS vulnerability, an attacker has to be authenticated to the application that uses the "TOPqw Webportal" as a software. When authenticated, the attacker can persistently place the malicious JavaScript code in the "QWKalkulation" menu.'

Configurations

No configuration.

History

21 Nov 2024, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79

15 Nov 2024, 14:00

Type Values Removed Values Added
Summary
  • (es) La función de carga de archivos de la herramienta "QWKalkulation" de baltic-it TOPqw Webportal v1.35.287.1 (corregido en la versión 1.35.291), en /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, es vulnerable a Cross-Site Scripting (XSS). Para explotar la vulnerabilidad XSS persistente, un atacante debe estar autenticado en la aplicación que utiliza el "TOPqw Webportal" como software. Una vez autenticado, el atacante puede colocar de forma persistente el código JavaScript malicioso en el menú "QWKalkulation".

13 Nov 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 21:15

Updated : 2024-11-21 22:15


NVD link : CVE-2024-45879

Mitre link : CVE-2024-45879

CVE.ORG link : CVE-2024-45879


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')