Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.
History

Mon, 10 Feb 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Gallagher
Gallagher command Centre
Weaknesses CWE-79
CPEs cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*
Vendors & Products Gallagher
Gallagher command Centre

cve-icon MITRE

Status: PUBLISHED

Assigner: Gallagher

Published:

Updated: 2024-08-01T22:27:36.320Z

Reserved: 2024-02-05T04:16:47.986Z

Link: CVE-2024-21838

cve-icon Vulnrichment

Updated: 2024-08-01T22:27:36.320Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-05T03:15:06.280

Modified: 2025-02-10T22:33:35.600

Link: CVE-2024-21838

cve-icon Redhat

No data.