CVE-2024-11021: Vice Webopac

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser.

Affected products

  • Vice Webopac: from 6, before 6.5.1 (fixed in 6.5.1); from 7, before 7.2.3 (fixed in 7.2.3)

Published 2024-11-11. Last modified 2026-06-17.