Vulnerabilities > CVE-2024-2211 - Unspecified vulnerability in Getgophish Gophish 0.12.1

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
getgophish

Summary

Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the campaign is removed from the menu.

Vulnerable Configurations

Part Description Count
Application
Getgophish
1