CRITICAL🇵🇱 Wersja polska

CVE-2024-6877

CVSS 9.4v4.0pub. 2024-09-18upd. 2026-06-03

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS. This issue affects Panel: before v2.3.24.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of input data during webpage generation (CWE-79). An attacker can deliver a crafted payload in an HTTP request, which is reflected by the server and embedded in the response without proper encoding or filtering. The victim must be tricked into clicking a malicious link or visiting a crafted URL, which causes JavaScript code to be executed in their browser in the context of the trusted application domain.

Impact

An attacker can hijack the session of a logged-in user, steal sensitive data (e.g., session cookies, tokens), perform actions on behalf of the victim, or conduct further attacks on the infrastructure managed by the Panel. Due to high impact ratings on dependent systems (SC:H, SI:H, SA:H), the consequences may extend beyond the end user themselves.

Mitigation & patch

Eliz Software Panel should be updated to version v2.3.24 or newer. Detailed information regarding the patch is available in the vendor's references and in the USOM security notice (TR-24-1497).

Who is affected

Eliz Software Panel in versions before v2.3.24.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Elizsoftware Panel

    APP
    Elizsoftware
    < 2.3.24
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2024-5958CRITICAL9.4PL ✓same product

SQL Injection umożliwiający wykonanie poleceń w Eliz Software Panel

CVE-2024-5959CRITICAL9.3PL ✓same product

Stored XSS w Eliz Software Panel — wstrzyknięcie skryptu po stronie serwera

CVE-2024-5960CRITICAL9.8PL ✓same product

Przechowywanie haseł w postaci jawnej w Elizsoftware Panel