Exploit
CVE-2024-24571

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) (CWE-80)

Published: Jan 31, 2024 / Updated: 9mo ago

010
CVSS 5.4EPSS 0.05%Medium
CVE info copied to clipboard

facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present in almost all of the input fields as there is insufficient input validation.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Timeline

CVE Assignment

NVD published the first details for CVE-2024-24571

Jan 31, 2024 at 3:15 PM
First Article

Feedly found the first article mentioning CVE-2024-24571. See article

Jan 31, 2024 at 11:20 PM / National Vulnerability Database
Proof of Concept (PoC) Released

A proof of concept exploit has been released

Feb 7, 2024 at 12:10 PM
EPSS

EPSS Score was set to: 0.05% (Percentile: 11.7%)

Feb 9, 2024 at 3:50 PM
Static CVE Timeline Graph

Affected Systems

Facilemanager/facilemanager
+null more

Exploits

https://github.com/WillyXJ/facileManager/security/advisories/GHSA-h7w3-xv88-2xqj
+null more

Patches

github.com
+null more

Attack Patterns

CAPEC-18: XSS Targeting Non-Script Elements
+null more

News

Update Wed Feb 14 10:13:54 UTC 2024
Update Wed Feb 14 10:13:54 UTC 2024
CVE-2024-24571 Exploit
CVE Id : CVE-2024-24571 Published Date: 2024-02-07T17:25:00+00:00 facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present in almost all of the input fields as there is insufficient input validation. inTheWild added a link to an exploit: https://github.com/WillyXJ/facileManager/security/advisories/GHSA-h7w3-xv88-2xqj
CVE-2024-24571 - RedPacket Security
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality. If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below To keep up to date follow us on the below channels.
CVE-2024-24571
Medium Severity Description facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present in almost all of the input fields as there is insufficient input validation. Read more at https://www.tenable.com/cve/CVE-2024-24571
CVE-2024-24571 | WillyXJ facileManager up to 4.5.0 cross site scripting (GHSA-h7w3-xv88-2xqj)
A vulnerability, which was classified as problematic , has been found in WillyXJ facileManager up to 4.5.0 . This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The identification of this vulnerability is CVE-2024-24571 . The attack may be initiated remotely. There is no exploit available. It is recommended to apply a patch to fix this issue.
See 5 more articles and social media posts

CVSS V3.1

Attack Vector:Network
Attack Complexity:Low
Privileges Required:Low
User Interaction:Required
Scope:Changed
Confidentiality:Low
Integrity:Low
Availability Impact:None

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI