Vulnerability Details CVE-2024-40324
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 45.8%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-40324
-
cpe:2.3:a:datex-soft:e-staff:5.1