CVE-2024-41504

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.
References
Link Resource
http://jetimob.com Product
https://github.com/rafaelbaldasso/CVE-2024-41504 Exploit Third Party Advisory
https://github.com/rafaelbaldasso/CVE-2024-41504 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:jetimob:imobiliaria:2024-06-27:*:*:*:*:*:*:*

History

01 Oct 2025, 15:14

Type Values Removed Values Added
First Time Jetimob imobiliaria
Jetimob
CPE cpe:2.3:a:jetimob:imobiliaria:2024-06-27:*:*:*:*:*:*:*
References () http://jetimob.com - () http://jetimob.com - Product
References () https://github.com/rafaelbaldasso/CVE-2024-41504 - () https://github.com/rafaelbaldasso/CVE-2024-41504 - Exploit, Third Party Advisory

12 Jun 2025, 16:06

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 20:15

Updated : 2025-10-01 15:14


NVD link : CVE-2024-41504

Mitre link : CVE-2024-41504

CVE.ORG link : CVE-2024-41504


JSON object : View

Products Affected

jetimob

  • imobiliaria
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')