CVE-2024-47793: Exceedone Exment
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When accessing the edit screen containing custom columns (column type: images or files), an arbitrary script may be executed on the web browser of the user.
Affected products
- Exceedone Exment: before 5.0.11 (fixed in 5.0.11); from 6.0.0, before 6.1.4 (fixed in 6.1.4)
Published 2024-10-18. Last modified 2026-06-17.