CVE-2024-28128 – org.fitnesse:fitnesse
Package
Manager: maven
Name: org.fitnesse:fitnesse
Vulnerable Version: >=0 <20220319
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS: 0.00266 pctl0.49844
Details
FitNesse Cross-site Scripting vulnerability Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with a specially crafted certain parameter.
Metadata
Created: 2024-03-18T09:30:31Z
Modified: 2025-03-21T22:28:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mjq8-gg9x-87gr/GHSA-mjq8-gg9x-87gr.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-mjq8-gg9x-87gr
Finding: F008
Auto approve: 1