6.1
CVSSv3

CVE-2024-41504

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: NA | VMScore: 710 | EPSS: 0.00031 | KEV: Not Included
Published: 10/06/2025 Updated: 11/06/2025

Vulnerability Summary

Cross-Site Scripting (XSS) in Jetimob Plataforma Imobiliaria via Activity Description Field

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.

Github Repositories

GitHub front page

/hey_there! ► Pentester & Red Teamer ► CEH | eJPT | ISFS ► CVE-2024-41502, CVE-2024-41503, CVE-2024-41504, CVE-2024-41505 # Currently specializing in Pentesting Active Directory environments, and then Cloud environments next (AWS, GCP, Azure) Pentest and Cybersecurity knowledge: ● Linux, Windows, Active Directory (AD), Network Devices ● Web Applications &