An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload via the "seconds" parameter in the program's URL, resulting in a possible takeover of a registered user's session.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32231 An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload via the "seconds" parameter in the program's URL, resulting in a possible takeover of a registered user's session.
Fixes

Solution

Vulnerability fixed in version 1.42.48-stable, deployed on 9 January 2024. As the affected product is a SaaS, it is not currently possible to access versions where the vulnerability is still present.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T20:20:00.468Z

Reserved: 2024-04-11T08:47:30.925Z

Link: CVE-2024-3654

cve-icon Vulnrichment

Updated: 2024-08-01T20:20:00.468Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-19T13:15:13.627

Modified: 2024-11-21T09:30:06.590

Link: CVE-2024-3654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses