{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/2clickportal/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2024-5961"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["2ClickPortal (7.2.31-7.6.4)"],"_cs_severities":["medium"],"_cs_tags":["web-vulnerability","xss","2clickportal"],"_cs_type":"advisory","_cs_vendors":["2ClickPortal"],"content_html":"\u003cp\u003eCVE-2024-5961 describes a reflected cross-site scripting (XSS) vulnerability affecting 2ClickPortal versions 7.2.31 through 7.6.4. The flaw resides within the application's search functionality, specifically in the 'string' parameter of the '/szukaj/' endpoint. By injecting malicious JavaScript into this parameter, an attacker can cause the application to reflect the script back to the user's browser, where it executes in the context of the user's session. This vulnerability is rated with a CVSS 5.3 (Medium) and requires passive user interaction, such as clicking a crafted link, to achieve exploitation. As a proof-of-concept exploit is now public, it is critical for administrators to audit instances of 2ClickPortal and apply necessary patches to mitigate the risk of session hijacking or further client-side exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-5961 allows an unauthenticated attacker to execute arbitrary JavaScript in the browser of a victim who clicks a malicious link. This can lead to unauthorized actions performed on behalf of the user, theft of session cookies, or redirection to malicious sites. The vulnerability affects a specific range of 2ClickPortal versions, making any installation within the 7.2.31 to 7.6.4 version window susceptible to this attack vector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade 2ClickPortal instances to a version outside the affected range (7.2.31-7.6.4).\u003c/li\u003e\n\u003cli\u003eImplement Content Security Policy (CSP) headers on the web server to restrict the execution of unauthorized inline scripts.\u003c/li\u003e\n\u003cli\u003eDeploy detection rules to identify anomalous HTTP requests targeting the '/szukaj/' endpoint with character sequences commonly used for XSS injection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T01:00:39Z","date_published":"2026-08-26T01:00:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-5961-xss/","summary":"CVE-2024-5961 is a reflected cross-site scripting (XSS) vulnerability in 2ClickPortal versions 7.2.31 through 7.6.4, enabling arbitrary script execution via the search function parameter.","title":"Reflected Cross-Site Scripting Vulnerability in 2ClickPortal","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-5961-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - 2ClickPortal","version":"https://jsonfeed.org/version/1.1"}