CVE-2024-9411: Ofcms Project Ofcms
Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
- Ofcms Project Ofcms: version 1.1.2 only
Published 2024-10-01. Last modified 2026-06-17.