CVE-2024-8776: Intumit Smartrobot

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks.

Affected products

  • Intumit Smartrobot: before 7.1.0 (fixed in 7.1.0)

Published 2024-09-16. Last modified 2026-06-17.