NA

CVE-2024-30920

Published: 18/04/2024 Updated: 19/04/2024

Vulnerability Summary

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote malicious user to execute arbitrary code via the render-document.php component.

Exploits

DerbyNet version 90 suffers from a cross site scripting vulnerability in render-documentphp ...

Mailing Lists

CVE ID: CVE-2024-30920 Description: A Cross Site Scripting (XSS) vulnerability has been identified in DerbyNet v90, specifically within the `render-documentphp` component This vulnerability allows a remote attacker to execute arbitrary code via crafted URLs The root cause of the vulnerability is the application's failure to properly sanitize ...