{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-04T00:29:58.859","vulnerabilities":[{"cve":{"id":"CVE-2024-8750","sourceIdentifier":"cve-coordination@incibe.es","published":"2024-09-12T12:15:54.007","lastModified":"2026-06-17T08:23:14.130","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view)."},{"lang":"es","value":"Vulnerabilidad de Cross-site Scripting (XSS) en idoit pro versión 28. Esta vulnerabilidad permite a un atacante recuperar detalles de la sesión de un usuario autenticado debido a la falta de una desinfección adecuada de los siguientes parámetros (id,lang,mNavID,name,pID,treeNode,type,view)."}],"affected":[{"source":"cve-coordination@incibe.es","affectedData":[{"vendor":"Synetics","product":"Idoit pro","defaultStatus":"unaffected","versions":[{"version":"28","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve-coordination@incibe.es","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T12:54:40.183360Z","id":"CVE-2024-8750","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve-coordination@incibe.es","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:i-doit:i-doit:28:*:*:*:pro:*:*:*","matchCriteriaId":"85C33B1A-464B-4A24-8100-6FB8D2128D41"}]}]}],"references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-synetics-idoit-pro","source":"cve-coordination@incibe.es","tags":["Third Party Advisory"]}]}}]}