CVE-2024-11479

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/12/2024
Last modified:
04/12/2024

Description

A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. HTML markup could be added to comments of tickets, which when submitted will render in the <br /> emails sent to all users on that ticket.

References to Advisories, Solutions, and Tools