← Back to CVE List

CVE-2024-29877

Published: 2024-03-21T14:15Z
Last Modified: 2025-01-24T18:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt