VYPR
Medium severity4.8NVD Advisory· Published Oct 29, 2024· Updated Apr 15, 2026

CVE-2024-48461

CVE-2024-48461

Description

Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored and reflected XSS vulnerabilities in TeslaLogger Admin Panel before v1.59.6 allow remote attackers to inject arbitrary scripts via insufficient input sanitization.

Vulnerability

Overview

CVE-2024-48461 describes multiple cross-site scripting (XSS) vulnerabilities in the TeslaLogger Admin Panel, affecting versions prior to v1.59.6. The root cause is improper validation and sanitization of user-supplied input, particularly in the "New Journey" field and other parameters, allowing both stored and reflected XSS attacks [2].

Exploitation

An attacker can exploit the stored XSS by injecting a malicious payload into the "New Journey" field via the /admin/journeys.php endpoint. This payload is stored and executed whenever another user views the journey list. Reflected XSS is also present in endpoints such as /admin/abrp.php and /wakeup.php, where input parameters are not sanitized, allowing immediate script execution in the victim's browser [2]. No authentication is required for the reflected XSS; the stored XSS requires access to the admin panel but can affect other users.

Impact

Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session cookie theft, web page defacement, account takeover, or other malicious actions within the application's domain [2].

Mitigation

The vulnerability has been fixed in version 1.59.6 of TeslaLogger, as noted in the project's changelog [1]. Users should update to the latest version to mitigate the risk. No workarounds are mentioned.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

1

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.