VYPR
Medium severity6.1OSV Advisory· Published Jul 26, 2024· Updated Apr 15, 2026

CVE-2024-41805

CVE-2024-41805

Description

Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious JavaScript in the context of a user’s browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft. Tracks version 2.7.1 is patched. No known complete workarounds are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Tracksapp/TracksOSV2 versions
    before-cucumber-removal, v1.5, v2.4.0, …+ 1 more
    • (no CPE)range: before-cucumber-removal, v1.5, v2.4.0, …
    • (no CPE)range: <2.7.1

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.