VulnerabilityModified
CVE-2024-6742
AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regular privileges to inject JavaScript and perform Reflected Cross-site scripting attacks.
MEDIUM 5.4EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regular privileges to inject JavaScript and perform Reflected Cross-site scripting attacks.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- space management system project/space management system
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/en/cp-139-7931-608eb-2.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7930-e0368-1.htmlThird Party Advisory
- https://www.twcert.org.tw/en/cp-139-7931-608eb-2.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7930-e0368-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.