RULE(RULE ID:338835)

Rule General Information
Release Date: 2025-04-29
Rule Name: Elaine Marketing Automation Cross Site Scripting Vulnerability (CVE-2024-42831)
Severity:
CVE ID:
Rule Protection Details
Description: A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: http://elaine.com
http://realtime.com
https://seclists.org/fulldisclosure/2024/Sep/49
Solutions
Please contact the software vendor to update the software patch.