CVE-2024-41504

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.
References
Link Resource
http://jetimob.com Product
https://github.com/rafaelbaldasso/CVE-2024-41504 Exploit Third Party Advisory
https://github.com/rafaelbaldasso/CVE-2024-41504 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:jetimob:imobiliaria:2024-06-27:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-06-10 20:15

Updated : 2025-10-01 15:14


NVD link : CVE-2024-41504

Mitre link : CVE-2024-41504

CVE.ORG link : CVE-2024-41504


JSON object : View

Products Affected

jetimob

  • imobiliaria
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')