CVE-2024-51322

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/03/2025
Last modified:
12/06/2025

Description

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp components

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zucchetti:ad_hoc_infinity:2.4:*:*:*:*:*:*:*