SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-30924

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

MEDIUM 4.6EPSS 0.34%

Does this matter?

Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.

Description

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

CVSS 3.1
4.6 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.34% probability · 27th percentile
CISA KEV
Not listed
Weakness
CWE-692
Affected
derbynet/derbynet
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.