An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload via the "seconds" parameter in the program's URL, resulting in a possible takeover of a registered user's session.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32231 | An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload via the "seconds" parameter in the program's URL, resulting in a possible takeover of a registered user's session. |
Fixes
Solution
Vulnerability fixed in version 1.42.48-stable, deployed on 9 January 2024. As the affected product is a SaaS, it is not currently possible to access versions where the vulnerability is still present.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:20:00.468Z
Reserved: 2024-04-11T08:47:30.925Z
Link: CVE-2024-3654
Updated: 2024-08-01T20:20:00.468Z
Status : Awaiting Analysis
Published: 2024-04-19T13:15:13.627
Modified: 2024-11-21T09:30:06.590
Link: CVE-2024-3654
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD