CVE-2024-57372 Details
Description
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters
A cross-site scripting (XSS) vulnerability exists in InformationPush master version. This issue allows remote attackers to inject malicious scripts or HTML into the webpage, potentially leading to the theft of sensitive information. The vulnerability arises because user-supplied data in the 'title', 'time', and 'msg' parameters is directly embedded into the HTML without any sanitization or validation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 17, 2025CISA-ADP
Assessed Jan 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kaixin1995 | [email protected] | Vendor |
| https://github.com/kaixin1995/InformationPush | [email protected] | ProductVendor |
| https://royblume.github.io/CVE-2024-57372/ | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| kaixin1995 InformationPush | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 17, 2025 | CVE Modified | CISA-ADP |
| Jan 17, 2025 | New CVE Received | [email protected] |
Volerion