PT-2024-20333 · Teamwire · Teamwire Windows Desktop Client

·

CVE-2024-24275

·

Published

2024-03-05

·

Updated

2025-02-18

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Teamwire Windows desktop client versions 2.0.1 through 2.4.0
Description The issue allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. This is a Cross Site Scripting vulnerability.
Recommendations For versions 2.0.1 through 2.4.0, consider disabling the global search function until a patch is available to prevent exploitation. Restrict access to sensitive information to minimize the risk of unauthorized access.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24275

Affected Products

Teamwire Windows Desktop Client