Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.
References
Link | Resource |
---|---|
http://jetimob.com | Product |
https://github.com/rafaelbaldasso/CVE-2024-41504 | Exploit Third Party Advisory |
https://github.com/rafaelbaldasso/CVE-2024-41504 | Exploit Third Party Advisory |
Configurations
History
01 Oct 2025, 15:14
Type | Values Removed | Values Added |
---|---|---|
First Time |
Jetimob imobiliaria
Jetimob |
|
CPE | cpe:2.3:a:jetimob:imobiliaria:2024-06-27:*:*:*:*:*:*:* | |
References | () http://jetimob.com - Product | |
References | () https://github.com/rafaelbaldasso/CVE-2024-41504 - Exploit, Third Party Advisory |
12 Jun 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-10 20:15
Updated : 2025-10-01 15:14
NVD link : CVE-2024-41504
Mitre link : CVE-2024-41504
CVE.ORG link : CVE-2024-41504
JSON object : View
Products Affected
jetimob
- imobiliaria
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')