CVE-2024-48392

OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.
Configurations

Configuration 1 (hide)

cpe:2.3:a:orangescrum:orangescrum:2.0.11:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-21 21:15

Updated : 2025-09-30 21:01


NVD link : CVE-2024-48392

Mitre link : CVE-2024-48392

CVE.ORG link : CVE-2024-48392


JSON object : View

Products Affected

orangescrum

  • orangescrum
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')