NA

CVE-2024-30927

Published: 18/04/2024 Updated: 19/04/2024

Vulnerability Summary

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows malicious users to execute arbitrary code via the racer-results.php component.

Exploits

DerbyNet version 90 suffers from a cross site scripting vulnerability in racer-resultsphp ...

Mailing Lists

CVE ID: CVE-2024-30927 Description: A Cross-Site Scripting (XSS) vulnerability is present in DerbyNet version 90, specifically within the `racer-resultsphp` component This issue allows remote attackers to execute arbitrary code through the improper handling of the `racerid` parameter The vulnerability is notably present within the HTML `< ...