CVE-2024-44795
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attacke
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
MEDIUM · CVSS 6.1
EPSS 0.00256
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0