Medium severity5.4NVD Advisory· Published Jun 24, 2024· Updated Jun 3, 2026
CVE-2024-4754
CVE-2024-4754
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.
This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
Affected products
1- Range: 6.6.4.4 <= x < 6.6.4.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.