{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-06T12:24:29.979","vulnerabilities":[{"cve":{"id":"CVE-2024-41805","sourceIdentifier":"security-advisories@github.com","published":"2024-07-26T15:15:11.327","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious JavaScript in the context of a user’s browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft. Tracks version 2.7.1 is patched. No known complete workarounds are available."},{"lang":"es","value":"Tracks, una aplicación web Getting Things Done (GTD), es vulnerable a Cross Site Scripting reflejado en versiones anteriores a la 2.7.1. El Cross Site Scripting reflejado permite la ejecución de JavaScript malicioso en el contexto del navegador de un usuario si ese usuario hace clic en un enlace malicioso, lo que permite ataques de phishing que podrían conducir al robo de credenciales. La versión 2.7.1 de Tracks está parcheada. No se conocen soluciones completas disponibles."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/TracksApp/tracks/commit/b0d288d2efd0f8020d04ca95b8e0738a9eab6c51","source":"security-advisories@github.com"},{"url":"https://github.com/TracksApp/tracks/commit/c23ca0574ec1149993476632ffd66643aec6aac2","source":"security-advisories@github.com"},{"url":"https://github.com/TracksApp/tracks/releases/tag/v2.7.1","source":"security-advisories@github.com"},{"url":"https://github.com/TracksApp/tracks/security/advisories/GHSA-fp4p-59hr-3695","source":"security-advisories@github.com"},{"url":"https://github.com/TracksApp/tracks/commit/b0d288d2efd0f8020d04ca95b8e0738a9eab6c51","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/TracksApp/tracks/commit/c23ca0574ec1149993476632ffd66643aec6aac2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/TracksApp/tracks/releases/tag/v2.7.1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/TracksApp/tracks/security/advisories/GHSA-fp4p-59hr-3695","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}