Vulnerability Details CVE-2024-40324
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.046
EPSS Ranking 88.8%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-40324
-
cpe:2.3:a:datex-soft:e-staff:5.1