VYPR
Moderate severityNVD Advisory· Published Jan 23, 2024· Updated Sep 10, 2024

CVE-2024-22490

CVE-2024-22490

Description

Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

beetl-bbs 2.0 contains a reflected XSS via the /index keyword parameter, allowing arbitrary script injection.

Vulnerability

Overview

beetl-bbs version 2.0 contains a reflected cross-site scripting (XSS) vulnerability in the /index endpoint's keyword parameter [1][2]. This flaw allows an attacker to inject arbitrary web script or HTML into the page, which can be executed in the context of the victim's browser session.

Exploitation

A remote attacker can craft a malicious URL containing a payload (e.g., `) in the keyword` parameter. If a logged-in user clicks such a link, the injected script executes in their browser, effectively bypassing same-origin policy restrictions. No authentication or special preconditions are required beyond user interaction with the crafted link [2].

Impact

Successful exploitation can lead to session hijacking or credential theft. The reference notes that after user login, the application stores a cookie containing an MD5 hash of the user's password. If the XSS payload exfiltrates this cookie and the AES encryption key remains unchanged, an attacker could attempt to crack the MD5 hash to recover the plaintext password [2].

Mitigation

As of the publication date, no patch has been released for beetl-bbs 2.0. Users should apply input validation and output encoding for the keyword parameter, or upgrade to a patched version if made available. This CVE is listed in the NVD with enrichment data but has not yet received a CVSS score [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.ibeetl:beetlMaven
<= 2.0.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.