Back

HIGH

Múltiple vulnerabilities on Adive Framework

Published Apr 30, 2024

Description

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.

Affected products

Remediation

Vendor solution

There is no solution reported at the moment.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Apr 30, 2024
Updated Sep 3, 2024
Reserved Apr 30, 2024
CISA Vulnrichment
Updated Aug 5, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a