CVE Feed

    Dashboard / CVE / CVE-2024-25627

    CVE-2024-25627

    Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads. As such, an attacker gaining administrative access to the alf.io application may be able to persist access by planting an XSS payload. This issue has been addressed in version 2.0-M4-2402. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:Feb 16, 2024
    Last Modified:Dec 18, 2024
    EPS:Feb 16, 2024
    EPSS Score:0.00464
    CVSS Score:3.5

    Affected Products

    Vendor
    Alf
    Product
    Alf

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High