CVE-2024-8521
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0.
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.8.1 is able to address this issue. The patch is identified as b31002cec6b71ab5f738881806bb546430ec692e. It is recommended to upgrade the affected component.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wavelog/wavelog
- Source
- cna@vuldb.com
References
- https://github.com/GithubUser843205/CVEs/tree/main/CVE-2024-8521Exploit
- https://github.com/wavelog/wavelog/commit/b31002cec6b71ab5f738881806bb546430ec692ePatch
- https://github.com/wavelog/wavelog/pull/744Issue Tracking
- https://github.com/wavelog/wavelog/releases/tag/1.8.1Release Notes
- https://vuldb.com/?ctiid.276726Permissions Required, VDB Entry
- https://vuldb.com/?id.276726Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.399819Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.