Description

Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpScreenResolutionWidth parameter manipulation in a form sent to an endpoint /TotalAgility/Kofax/BrowserDevice/ScanFront.aspx This allows for injection of a malicious JavaScript code, leading to a possible information leak.  Exploitation is possible only while using POST requests and also requires retrieving/generating a proper VIEWSTATE parameter, which limits the risk of a successful attack.

INFO

Published Date :

2024-12-06T20:55:11.944Z

Last Modified :

2024-12-10T14:44:28.209Z

Source :

CERT-PL
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7875 vulnerability.

Vendors Products
Tungstenautomation
  • Totalagility
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-7875.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability