S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jun 25, 2024

CVE-2024-28734 Scanner

CVE-2024-28734 scanner - Cross-Site Scripting (XSS) vulnerability in Unit4 Financials by Coda

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
1
Times Used
by S4E users
1
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-28734
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
financialsby unit4
AFFECTED< 2023Q4SAFE ✓≥ 2023Q4
Updated Aug 22, 2026View on NVD →
Detail

Unit4 Financials by Coda is an advanced financial management software used by large enterprises for comprehensive financial operations. It is used by financial professionals to manage budgets, forecasts, and financial reports. The software offers real-time data and reporting capabilities, making it a critical tool for finance departments. Unit4 Financials is known for its scalability and integration with other enterprise systems. The 2024Q1 version includes various enhancements to improve user experience and system performance.

The Cross-Site Scripting (XSS) vulnerability in Unit4 Financials by Coda allows attackers to inject malicious scripts into web pages viewed by other users. This vulnerability can be exploited by crafting a script to the cols parameter. Once exploited, the attacker can execute arbitrary scripts in the context of the user's browser session. This type of vulnerability can lead to unauthorized actions being performed on behalf of the user.

The vulnerability exists in the cols parameter of the Unit4 Financials by Coda application. An attacker can inject a crafted script through this parameter, which gets executed when a user accesses the vulnerable endpoint. The specific endpoint affected is "/coda/frameset," where the malicious script can be embedded in the cols attribute of the frameset tag. When the vulnerable URL is accessed, the script runs in the user's browser context, potentially allowing the attacker to hijack sessions or steal sensitive information. The vulnerability is confirmed by the presence of the alert script in the HTML body and the HTTP 200 status code.

If exploited, this vulnerability can lead to significant security issues, including session hijacking, unauthorized actions performed in the context of the user's session, and theft of sensitive information. The attacker could manipulate the content displayed to the user or redirect the user to malicious websites. This can result in a loss of data integrity, confidentiality, and user trust.

Become a member of the S4E platform to enhance your cybersecurity defenses. By using our advanced scanning tools, you can identify and mitigate vulnerabilities like the Cross-Site Scripting (XSS) in Unit4 Financials by Coda. Our platform provides comprehensive reports, actionable insights, and continuous monitoring to protect your digital assets. Join us to ensure your systems are secure and compliant with industry standards.

References:

Solution Advice
  • Validate and sanitize all user inputs, especially those used in the cols parameter.
  • Implement Content Security Policy (CSP) to restrict the execution of scripts.
  • Apply security patches and updates provided by the software vendor.
  • Regularly perform security assessments and code reviews to detect and mitigate vulnerabilities.
  • Educate developers on secure coding practices to prevent XSS vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.