Back

MEDIUM

zzdevelop lenosp Adduser Page cross site scripting

Published May 24, 2024

Description

** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affects an unknown part of the component Adduser Page. The manipulation of the argument username with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-266127. NOTE: The vendor rejected the issue because he claims that XSS which require administrative privileges are not of any use for attackers.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published May 24, 2024
Updated Aug 2, 2024
Reserved May 5, 2024

CISA Vulnrichment

Updated May 24, 2024

NVD

Status Deferred
Modified Sep 3, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published May 24, 2024
Updated Aug 2, 2024

GitHub

No data