NA

CVE-2024-4337

Published: 30/04/2024 Updated: 30/04/2024

Vulnerability Summary

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an malicious user to retrieve the session details of an authenticated user.

Vulnerability Trend