CVE-2024-39610

Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cleancoder:fitnesse:*:*:*:*:*:*:*:*

History

20 Nov 2024, 15:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
CPE cpe:2.3:a:cleancoder:fitnesse:*:*:*:*:*:*:*:*
References () https://fitnesse.org/FitNesseDownload - () https://fitnesse.org/FitNesseDownload - Release Notes
References () https://github.com/unclebob/fitnesse/releases/tag/20241026 - () https://github.com/unclebob/fitnesse/releases/tag/20241026 - Release Notes
References () https://jvn.jp/en/jp/JVN36791327/ - () https://jvn.jp/en/jp/JVN36791327/ - Third Party Advisory
First Time Cleancoder
Cleancoder fitnesse

15 Nov 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 06:15

Updated : 2024-11-20 15:02


NVD link : CVE-2024-39610

Mitre link : CVE-2024-39610


JSON object : View

Products Affected

cleancoder

  • fitnesse
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')