Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.
References
Configurations
History
11 Dec 2024, 19:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.claris.com/s/article/Security-Vulnerability-in-Claris-FileMaker-Server?language=en_US - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
First Time |
Claris
Claris filemaker Server |
|
CPE | cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:* |
Information
Published : 2024-04-15 23:15
Updated : 2024-12-11 19:56
NVD link : CVE-2024-27794
Mitre link : CVE-2024-27794
CVE.ORG link : CVE-2024-27794
JSON object : View
Products Affected
claris
- filemaker_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')