← Back to CVE List

CVE-2024-11986

Published: 2024-12-13T14:15Z
Last Modified: 2024-12-13T14:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt