CVE-2024-45920

A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in "Intrest" feature.
References
Link Resource
https://gist.github.com/ipxsec/10526db2cbfcb899a70dcb8f0ee53a99 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:solvait:solvait:24.4.2:*:*:*:*:*:*:*

History

10 Jul 2025, 15:38

Type Values Removed Values Added
References () https://gist.github.com/ipxsec/10526db2cbfcb899a70dcb8f0ee53a99 - () https://gist.github.com/ipxsec/10526db2cbfcb899a70dcb8f0ee53a99 - Exploit, Third Party Advisory
First Time Solvait
Solvait solvait
CPE cpe:2.3:a:solvait:solvait:24.4.2:*:*:*:*:*:*:*

Information

Published : 2024-09-30 13:15

Updated : 2025-07-10 15:38


NVD link : CVE-2024-45920

Mitre link : CVE-2024-45920

CVE.ORG link : CVE-2024-45920


JSON object : View

Products Affected

solvait

  • solvait
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')