VYPR
Medium severity4.7NVD Advisory· Published Apr 4, 2024· Updated Apr 15, 2026

CVE-2024-25503

CVE-2024-25503

Description

Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the edit details parameter of the New Project function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Advanced REST Client v.17.0.9 has a stored XSS vulnerability in the 'edit details' parameter of the New Project function, allowing arbitrary code execution and sensitive information disclosure.

Vulnerability

Overview

CVE-2024-25503 is a Cross-Site Scripting (XSS) vulnerability found in Advanced REST Client version 17.0.9. The flaw resides in the 'edit details' parameter of the New Project function, where insufficient input sanitization enables an attacker to inject arbitrary script code [1].

Exploitation

The vulnerability can be exploited by a remote attacker who crafts a malicious script and submits it through the 'edit details' field. The attack does not require prior authentication; however, it likely depends on user interaction, such as a victim viewing the crafted project details within the application [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the affected user's session. This can lead to sensitive information disclosure, including session tokens, API keys, or other data accessible within the application, and could facilitate further attacks like account takeover [1].

Mitigation

As of the publication date (April 4, 2024), no official patch has been announced. Users are advised to avoid using the 'edit details' feature with untrusted input or to apply input validation/encoding until a fix is released by the vendor [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.