ZeroHour

CVE-2024-41514

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p36
Published
()
Modified
Description

A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter.

Vendors
4pace
Products
cadclick
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.