Vulnerability Details CVE-2024-34090
An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control Panel (ACP) did not previously escape content appropriately. 6.14 P3 (6.14.0.3) is also a fixed release.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.7%
CVSS Severity
CVSS v3 Score 7.3
Products affected by CVE-2024-34090
-
cpe:2.3:a:archerirm:archer:-
-
cpe:2.3:a:archerirm:archer:2024.03
-
cpe:2.3:a:archerirm:archer:6.10.0.3
-
cpe:2.3:a:archerirm:archer:6.11.0.4
-
cpe:2.3:a:archerirm:archer:6.12.0.0
-
cpe:2.3:a:archerirm:archer:6.12.0.6
-
cpe:2.3:a:archerirm:archer:6.12.0.6.1
-
cpe:2.3:a:archerirm:archer:6.13.0
-
cpe:2.3:a:archerirm:archer:6.13.0.1
-
cpe:2.3:a:archerirm:archer:6.13.0.2
-
cpe:2.3:a:archerirm:archer:6.13.0.2.2
-
cpe:2.3:a:archerirm:archer:6.13.0.3
-
cpe:2.3:a:archerirm:archer:6.13.0.3.1
-
cpe:2.3:a:archerirm:archer:6.13.0.4
-
cpe:2.3:a:archerirm:archer:6.14.0
-
cpe:2.3:a:archerirm:archer:6.14.0.1.2
-
cpe:2.3:a:archerirm:archer:6.14.0.2
-
cpe:2.3:a:archerirm:archer:6.14.0.2.1
-
cpe:2.3:a:archerirm:archer:6.14.0.2.2
-
cpe:2.3:a:archerirm:archer:6.3.0.0
-
cpe:2.3:a:archerirm:archer:6.8.0.0
-
cpe:2.3:a:archerirm:archer:6.9.3.4