{"id":"CVE-2024-24397","details":"Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.","aliases":["GHSA-9cgf-pxwq-2cpw"],"modified":"2026-08-12T03:51:34.245103792Z","published":"2024-02-05T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24397.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Dashboard.JS"},{"fixed":"v.2024.1.2"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://cloud-trustit.spp.at/s/Pi78FFazHamJQ5R"},{"type":"WEB","url":"https://cves.at/posts/cve-2024-24397/writeup/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24397.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24397"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stimulsoft/dashboards.js","events":[{"introduced":"0"},{"fixed":"6143388768123b1d7b8563b52f83ec104f4f0bef"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:stimulsoft:dashboards.js:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2024.1.2"}]}}],"versions":["v2024.1.1","v2023.4.4","v2023.4.3","v2023.4.2","v2023.4.1","v2023.3.4","v2023.3.3","v2023.3.2","v2023.3.1","v2023.2.8","v2023.2.7","v2023.2.6","v2023.2.4","v2023.2.3","v2023.2.2","v2023.2.1","v2023.1.8","v2023.1.7","v2023.1.6","v2023.1.5","v2023.1.4","v2023.1.3","v2023.1.2","v2023.1.1","v2022.4.5","v2022.4.4","v2022.4.3","v2022.4.2","v2022.4.1","v2022.3.5","v2022.3.4","v2022.3.3","v2022.3.2","v2022.3.1","v2022.2.6","v2022.2.5","v2022.2.4","v2022.2.3","v2022.2.2","v2022.2.1","v2022.1.6","v2022.1.5","v2022.1.4","v2022.1.3","v2022.1.1","v2021.4.3","v2021.4.2","v2021.4.1","v2021.3.7","v2021.3.6","v2021.3.5","v2021.3.3","2021.3.1","2021.2.3","2021.2.2","2021.2.1","2021.1.1","2020.5.1","2020.4.2","2020.4.1","2020.2.2","2020.2.1","2019.4.2","2019.3.6","2019.3.5","2019.3.4","2019.3.3","2019.3.2","2019.3.1","2019.2.3","2019.2.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24397.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}