CVE-2024-6050 MEDIUM

CVE-2024-6050: Reflected XSS in SOWA OPAC

Vendor Sokrates-Software
Product SOWA OPAC
Weakness CWE-79 · XSS
Published July 1, 2024
Last update August 1, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/AU:Y/R:A/U:Green

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.

Key dates

02Disclosure timeline

July 1, 2024 CVE published
August 1, 2024 Record updated