UI Request/Response Validation
in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31913 | Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact. |
No history.
Status: PUBLISHED
Assigner: tibco
Published:
Updated: 2024-08-01T20:05:08.445Z
Reserved: 2024-04-04T17:01:23.280Z
Link: CVE-2024-3323
Updated: 2024-08-01T20:05:08.445Z
Status : Deferred
Published: 2024-04-17T19:15:08.177
Modified: 2026-06-17T07:43:47.157
Link: CVE-2024-3323
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:15:57Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD