CVE-2024-23604

Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cleancoder:fitnesse:-:*:*:*:*:*:*:*

History

27 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
CPE cpe:2.3:a:cleancoder:fitnesse:-:*:*:*:*:*:*:*
First Time Cleancoder
Cleancoder fitnesse
References () http://fitnesse.org/FitNesseDownload - () http://fitnesse.org/FitNesseDownload - Product, Release Notes
References () https://github.com/unclebob/fitnesse - () https://github.com/unclebob/fitnesse - Product
References () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md - () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md - Product
References () https://jvn.jp/en/jp/JVN94521208/ - () https://jvn.jp/en/jp/JVN94521208/ - Third Party Advisory

21 Nov 2024, 08:57

Type Values Removed Values Added
References () http://fitnesse.org/FitNesseDownload - () http://fitnesse.org/FitNesseDownload -
References () https://github.com/unclebob/fitnesse - () https://github.com/unclebob/fitnesse -
References () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md - () https://github.com/unclebob/fitnesse/blob/master/SECURITY.md -
References () https://jvn.jp/en/jp/JVN94521208/ - () https://jvn.jp/en/jp/JVN94521208/ -
Summary
  • (es) Existe una vulnerabilidad de cross-site scripting en todas las versiones de FitNesse, lo que puede permitir que un atacante remoto no autenticado ejecute un script arbitrario en el navegador web del usuario que utiliza el producto y accede a un enlace con múltiples parámetros especialmente manipulados.

18 Mar 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 08:15

Updated : 2025-03-27 20:15


NVD link : CVE-2024-23604

Mitre link : CVE-2024-23604

CVE.ORG link : CVE-2024-23604


JSON object : View

Products Affected

cleancoder

  • fitnesse
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')