CVE-2024-25976 describes a reflected Cross-Site Scripting (XSS) vulnerability in an unspecified product when LDAP authentication is enabled. An attacker can craft a malicious URL that, when opened by a victim, executes arbitrary JavaScript code in their browser due to improper handling of the $_SERVER['PHP_SELF'] variable in login.php. This vulnerability has a CVSS score of 6.1 (Medium), indicating a low attack complexity and no authentication required, but it necessitates user interaction. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Interaction Design Team At The University Of Applied Sciences And Arts In Hildesheim/Germany | HAWKI | versions before commit 146967fCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.