PT-2024-28024 · Ibarn · Ibarn

·

CVE-2024-38470

·

Published

2024-06-17

·

Updated

2025-04-30

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions iBarn version 1.5
Description A reflected cross-site scripting (XSS) issue was found, which can be triggered via the search parameter at the "/own.php" endpoint.
Recommendations For version 1.5, consider restricting access to the /own.php endpoint or avoiding the use of the search parameter until a fix is available. As a temporary workaround, input validation and sanitization of the search parameter can help minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38470

Affected Products

Ibarn