CVE-2024-7124

Publication date

2024-11-14 15:07:50

Family

CERT-PL

State

PUBLISHED

Description

Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter filter in the endpoint indexsearch allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in users browser. This issue affects DInGO dLibra software in versions from 6.0 before 6.3.20.