CVE-2024-9411: Ofcms Project Ofcms

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Affected products

Published 2024-10-01. Last modified 2026-06-17.