Vulnerability CVE-2024-28734


Published: 2024-03-19

Description:
Cross Site Scripting vulnerability in Unit4 Financials by Coda v.2024Q1 allows a remote attacker to escalate privileges via a crafted script to the cols parameter.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Financials By Coda Cross Site Scripting
Leo Draghi
16.03.2024

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
http://financials.com
http://unit4.com
https://packetstormsecurity.com/files/177619/Financials-By-Coda-Cross-Site-Scripting.html

Copyright 2024, cxsecurity.com

 

Back to Top