Journyx是Journyx公司的一款基于云的时间跟踪软件。 Journyx 11.5.4版本存在安全漏洞,该漏洞源于攻击者可以制作恶意链接,一旦点击该链接,就会在应用程序上下文中执行任意JavaScript。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Journyx | Journyx (jtime) | 11.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6892.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-6893 | Journyx Unauthenticated XML External Entities Injection | |
| CVE-2024-6891 | Journyx Authenticated Remote Code Execution | |
| CVE-2024-6890 | Journyx Unauthenticated Password Reset Bruteforce |
No comments yet