Junglewise Threat Intelligence

CVE-2024-12915: Devinim Software Library Software reflected XSS

CVE-2024-12915 · Severity: medium · CVSS 4.6 · Published 2025-06-30

Executive brief

Devinim Software Library Software is a solution used for managing library resources and digital catalogs. A security vulnerability in this software allows attackers to inject malicious scripts into web pages viewed by other users. If exploited, this could lead to unauthorized actions being performed in a user's browser session, potentially compromising sensitive account information or disrupting library operations.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Devinim Software Library Software versions prior to 24.11.02. The flaw stems from the improper neutralization of user-supplied input during web page generation (CWE-79). An attacker can exploit this by tricking an authenticated user into clicking a specially crafted link, causing malicious JavaScript to execute in the victim's browser. This requires low privileges and user interaction. Successful exploitation can lead to the disclosure of session tokens or the performance of unauthorized actions on behalf of the victim. A fix is available in version 24.11.02.

Affected products

  • Devinim Software Library Software before 24.11.02

Timeline

  • 2025-06-30: disclosed: Initial NVD publication date
  • 2024-11-02: patched: Patch released in version 24.11.02

References