VYPR
Medium severity5.4NVD Advisory· Published Jan 10, 2025· Updated Jul 5, 2026

CVE-2024-54998

CVE-2024-54998

Description

MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Monicahq/Monica2 versions
    cpe:2.3:a:monicahq:monica:4.1.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:monicahq:monica:4.1.2:*:*:*:*:*:*:*
    • (no CPE)
  • Monica/Monicallm-fuzzy
    Range: =4.1.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.