← Back to CVE List

CVE-2024-36819

Published: 2024-06-25T19:15Z
Last Modified: 2024-11-21T09:22Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt