Vulnerability Details CVE-2024-29273
There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.1%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2024-29273
-
cpe:2.3:a:dzzoffice:dzzoffice:2.02.1_sc_utf8