CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-25976: Reflected Cross-Site-Scripting (XSS)

Description

When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only needs to open in order to execute arbitrary JavaScript code in the victim's browser. This is due to a fault in the file login.php where the content of "$_SERVER['PHP_SELF']" is reflected into the HTML of the website. Hence the attacker does not need a valid account in order to exploit this issue.

Classification

CVE ID: CVE-2024-25976

Affected Products

Vendor: Interaction Design Team at the University of Applied Sciences and Arts in Hildesheim/Germany

Product: HAWKI

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 18.39% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://r.sec-consult.com/hawki
https://github.com/HAWK-Digital-Environments/HAWKI/commit/146967f3148e92d1640ffebc21d8914e2d7fb3f1
http://seclists.org/fulldisclosure/2024/May/34

Timeline