CVE-2024-10087

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might craft a link containing a malicious script, which then gets directly embedded in references to other resources, what causes the script to run in user's context multiple times.  This vulnerability has been patched in version 79.0
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2025, 18:39

Type Values Removed Values Added
Summary
  • (es) Internet Starter, uno de los módulos del sistema SoftCOM iKSORIS, es vulnerable a ataques XSS reflejado (Cross-site Scripting). Un atacante podría crear un enlace con un script malicioso, que posteriormente se incrusta directamente en referencias a otros recursos, lo que provoca que el script se ejecute varias veces en el contexto del usuario. Esta vulnerabilidad ha sido corregida en la versión 79.0.

14 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-14 12:15

Updated : 2025-04-15 18:39


NVD link : CVE-2024-10087

Mitre link : CVE-2024-10087

CVE.ORG link : CVE-2024-10087


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')