{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-17T19:33:05.067","vulnerabilities":[{"cve":{"id":"CVE-2024-5062","sourceIdentifier":"security@huntr.dev","published":"2024-06-30T16:15:03.217","lastModified":"2024-11-21T09:46:53.077","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, specifically within the survey redirect parameter. This flaw allows an attacker to redirect users to a specified URL after completing a survey, without proper validation of the 'redirect' parameter. Consequently, an attacker can execute arbitrary JavaScript code in the context of the user's browser session. This vulnerability could be exploited to steal cookies, potentially leading to account takeover."},{"lang":"es","value":"Se identificó una vulnerabilidad de Cross-Site Scripting (XSS) Reflejado en zenml-io/zenml versión 0.57.1. La vulnerabilidad existe debido a una neutralización inadecuada de la entrada durante la generación de la página web, específicamente dentro del parámetro de redireccionamiento de la encuesta. Esta falla permite a un atacante redirigir a los usuarios a una URL específica después de completar una encuesta, sin una validación adecuada del parámetro \"redirect\". En consecuencia, un atacante puede ejecutar código JavaScript arbitrario en el contexto de la sesión del navegador del usuario. Esta vulnerabilidad podría aprovecharse para robar cookies, lo que podría llevar a la apropiación de cuentas."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zenml:zenml:*:*:*:*:*:*:*:*","versionEndExcluding":"0.58.0","matchCriteriaId":"C38B4091-A6B6-4996-BAE6-C670ED09D268"}]}]}],"references":[{"url":"https://github.com/zenml-io/zenml/commit/21edd863c0ba53c1110b6f018a07c2d6853cf6d4","source":"security@huntr.dev","tags":["Patch"]},{"url":"https://huntr.com/bounties/ceddd3c1-a9da-4d6c-85c4-41d4d1e1102f","source":"security@huntr.dev","tags":["Exploit"]},{"url":"https://github.com/zenml-io/zenml/commit/21edd863c0ba53c1110b6f018a07c2d6853cf6d4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://huntr.com/bounties/ceddd3c1-a9da-4d6c-85c4-41d4d1e1102f","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]}]}}]}