Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-48392

Description

OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.

POC

Reference

- https://github.com/Renzusclarke/CVE-2024-48392-PoC

- https://github.com/Renzusclarke/CVE-2024-48392-PoC/blob/main/poc.txt

Github

- https://github.com/Renzusclarke/CVE-2024-48392-PoC

- https://github.com/nomi-sec/PoC-in-GitHub