CVE-2024-40509: Openpetra

High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmx function.

Affected products

Published 2024-09-27. Last modified 2026-06-17.