NA

CVE-2024-30925

Published: 18/04/2024 Updated: 19/04/2024

Vulnerability Summary

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows malicious users to execute arbitrary code via the photo-thumbs.php component.

Exploits

DerbyNet version 90 suffers from a cross site scripting vulnerability in photo-thumbsphp ...

Mailing Lists

CVE ID: CVE-2024-30925 Description: A Cross-Site Scripting (XSS) vulnerability exists in DerbyNet version 90, specifically within the `photo-thumbsphp` component This issue enables a remote attacker to execute arbitrary code through the improper handling of the `racerid` and `back` parameters The vulnerability arises because the application ...