← Volver a CVEs
CVE-2024-28112
MEDIUM6.1
Descripcion
Peering Manager is a BGP session management tool. Affected versions of Peering Manager are subject to a potential stored Cross-Site Scripting (XSS) attack in the `name` attribute of AS or Platform. The XSS triggers on a routers detail page. Adversaries are able to execute arbitrary JavaScript code with the permission of a victim. XSS attacks are often used to steal credentials or login tokens of other users. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Detalles CVE
Puntuacion CVSS v3.16.1
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioREQUIRED
Publicado3/12/2024
Ultima modificacion2/20/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
peering-manager:peering_manager
Debilidades (CWE)
CWE-79CWE-79
Referencias
https://github.com/peering-manager/peering-manager/security/advisories/GHSA-fmf5-24pq-rq2w(security-advisories@github.com)
https://owasp.org/www-community/attacks/xss(security-advisories@github.com)
https://github.com/peering-manager/peering-manager/security/advisories/GHSA-fmf5-24pq-rq2w(af854a3a-2127-422b-91ae-364da2661108)
https://owasp.org/www-community/attacks/xss(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.