CVE-2024-11971

Source
https://cve.org/CVERecord?id=CVE-2024-11971
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11971.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11971
Published
2024-11-28T22:00:18.421Z
Modified
2026-07-15T01:49:13.285645975Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Guizhou Xiaoma Technology jpress Avatar upload cross site scripting
Details

A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.1.2"
                },
                {
                    "last_affected": "5.1.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11971.json",
    "cwe_ids": [
        "CWE-79",
        "CWE-94"
    ]
}
References

Affected packages

Git / github.com/jpressprojects/jpress

Affected ranges

Type
GIT
Repo
https://github.com/jpressprojects/jpress
Events
Database specific
{
    "cpe": "cpe:2.3:a:jpress:jpress:5.1.2:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "5.1.2"
        },
        {
            "last_affected": "5.1.2"
        }
    ]
}

Affected versions

5.*
5.1.2
v5.*
v5.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11971.json"