{"id":"CVE-2024-27609","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-27609","summary":"Bonita cross-site scripting vulnerability","details":"Bonita before 10.1.0.W11 allows stored XSS via a UI screen in the administration panel.","published":"2024-04-01T00:30:43Z","modified":"2024-11-08T22:23:17.347758Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.bonitasoft.console:bonita-web-server","fixedVersion":"10.1.0.W11"},{"ecosystem":"Maven","name":"org.bonitasoft.platform:platform-resources","fixedVersion":"10.1.0.W11"}],"fix":{"url":"https://github.com/bonitasoft/bonita-engine/commit/15dc60a99d97f9407b5089ba26f792cf3bd87f6b","label":"bonitasoft/bonita-engine@15dc60a"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27609"},{"type":"WEB","url":"https://github.com/bonitasoft/bonita-engine/commit/15dc60a99d97f9407b5089ba26f792cf3bd87f6b"},{"type":"WEB","url":"https://github.com/bonitasoft/bonita-engine/commit/26b24690a80dce11c0a4fa38ea54aeb35ca1e541"},{"type":"WEB","url":"https://github.com/bonitasoft/bonita-engine/commit/2c84ea1a76f7e7f345c334645e46428e9376b0c9"},{"type":"WEB","url":"https://github.com/bonitasoft/bonita-engine/commit/90469adf2b0ebf33f4c65b583f5c96284c8c1086"},{"type":"WEB","url":"https://documentation.bonitasoft.com/bonita/latest/release-notes#_fixes_in_bonita_runtime_including_bonita_applications_2"},{"type":"PACKAGE","url":"https://github.com/bonitasoft/bonita-engine"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-08T22:23:17.347758Z"}}