Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-23349

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack. Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-23349
  • Apache » Answer » Version: N/A
    cpe:2.3:a:apache:answer:-
  • Apache » Answer » Version: 0.2.0
    cpe:2.3:a:apache:answer:0.2.0
  • Apache » Answer » Version: 0.3.0
    cpe:2.3:a:apache:answer:0.3.0
  • Apache » Answer » Version: 0.4.0
    cpe:2.3:a:apache:answer:0.4.0
  • Apache » Answer » Version: 0.4.1
    cpe:2.3:a:apache:answer:0.4.1
  • Apache » Answer » Version: 0.4.2
    cpe:2.3:a:apache:answer:0.4.2
  • Apache » Answer » Version: 0.5.0
    cpe:2.3:a:apache:answer:0.5.0
  • Apache » Answer » Version: 1.0.0
    cpe:2.3:a:apache:answer:1.0.0
  • Apache » Answer » Version: 1.0.1
    cpe:2.3:a:apache:answer:1.0.1
  • Apache » Answer » Version: 1.0.2
    cpe:2.3:a:apache:answer:1.0.2
  • Apache » Answer » Version: 1.0.3
    cpe:2.3:a:apache:answer:1.0.3
  • Apache » Answer » Version: 1.0.4
    cpe:2.3:a:apache:answer:1.0.4
  • Apache » Answer » Version: 1.0.5
    cpe:2.3:a:apache:answer:1.0.5
  • Apache » Answer » Version: 1.0.6
    cpe:2.3:a:apache:answer:1.0.6
  • Apache » Answer » Version: 1.0.7
    cpe:2.3:a:apache:answer:1.0.7
  • Apache » Answer » Version: 1.0.8
    cpe:2.3:a:apache:answer:1.0.8
  • Apache » Answer » Version: 1.0.9
    cpe:2.3:a:apache:answer:1.0.9
  • Apache » Answer » Version: 1.1.0
    cpe:2.3:a:apache:answer:1.1.0
  • Apache » Answer » Version: 1.1.1
    cpe:2.3:a:apache:answer:1.1.1
  • Apache » Answer » Version: 1.1.2
    cpe:2.3:a:apache:answer:1.1.2
  • Apache » Answer » Version: 1.1.3
    cpe:2.3:a:apache:answer:1.1.3
  • Apache » Answer » Version: 1.2.0
    cpe:2.3:a:apache:answer:1.2.0
  • Apache » Answer » Version: 1.2.1
    cpe:2.3:a:apache:answer:1.2.1


Contact Us

Shodan ® - All rights reserved