{"id":"CVE-2024-41805","summary":"Tracks vulnerable to reflected cross-site scripting","details":"Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious JavaScript in the context of a user’s browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft. Tracks version 2.7.1 is patched. No known complete workarounds are available.","aliases":["GHSA-fp4p-59hr-3695"],"modified":"2026-08-12T03:51:46.140254901Z","published":"2024-07-26T14:51:02.015Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41805.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/TracksApp/tracks/releases/tag/v2.7.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41805.json"},{"type":"ADVISORY","url":"https://github.com/TracksApp/tracks/security/advisories/GHSA-fp4p-59hr-3695"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41805"},{"type":"FIX","url":"https://github.com/TracksApp/tracks/commit/b0d288d2efd0f8020d04ca95b8e0738a9eab6c51"},{"type":"FIX","url":"https://github.com/TracksApp/tracks/commit/c23ca0574ec1149993476632ffd66643aec6aac2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tracksapp/tracks","events":[{"introduced":"0"},{"fixed":"b0d288d2efd0f8020d04ca95b8e0738a9eab6c51"},{"fixed":"c23ca0574ec1149993476632ffd66643aec6aac2"},{"fixed":"36529c50b31e1d3966a8819ea63bf90692e7b7c9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.7.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.7.0","v2.6.0","v2.5.2","v2.5.1","v2.5.0","v2.4.1","v2.4.2","v2.4.0","before-cucumber-removal","v1.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41805.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}