Skip to main content
Vulnerability Database/CVE-2024-28734

CVE-2024-28734: Unit4 Financials XSS Vulnerability

CVE-2024-28734 is a cross-site scripting vulnerability in Unit4 Financials by Coda that enables remote attackers to execute arbitrary code through malicious GET requests. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2024-28734 Overview

CVE-2024-28734 is a reflected Cross-Site Scripting (XSS) vulnerability affecting Unit4 Financials by Coda versions prior to 2023Q4. The flaw resides in the handling of the cols GET parameter, which is reflected into HTTP responses without adequate output encoding. A remote attacker can craft a malicious URL that, when visited by an authenticated user, executes arbitrary JavaScript in the victim's browser session. The issue is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation).

Critical Impact

Successful exploitation lets attackers execute arbitrary script in the victim's browser context, enabling session hijacking, credential theft, and unauthorized financial transactions within the Coda application.

Affected Products

  • Unit4 Financials by Coda, all versions prior to release 2023Q4
  • Web-based Coda financial management interface exposing the cols request parameter
  • Deployments accessible over the network to untrusted users

Discovery Timeline

  • 2024-03-19 - CVE-2024-28734 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in the NVD database

Technical Details for CVE-2024-28734

Vulnerability Analysis

The vulnerability is a reflected XSS flaw within Unit4 Financials by Coda. The application accepts a cols query-string parameter through a GET request and echoes its value into the rendered HTML response without proper contextual encoding or sanitization. Because the reflected data is treated as markup rather than inert text, attacker-supplied JavaScript executes in the browser of any user who loads the crafted URL.

Exploitation requires user interaction, typically achieved by delivering the malicious link via phishing email, chat, or a compromised web page. When the request originates from an authenticated Coda session, the injected script runs with the privileges of that user and can access session cookies, CSRF tokens, and DOM content of the financial application. According to publicly available information, the flaw has an EPSS probability of 1.791% (77.4 percentile) and no public exploit or CISA KEV listing has been confirmed.

Root Cause

The root cause is missing output encoding on the cols parameter before it is inserted into the server-rendered response. The application trusts client-supplied query data and does not apply HTML-context or JavaScript-context escaping, violating the input neutralization requirements described in CWE-79.

Attack Vector

The attack is delivered over the network through a crafted GET request. An attacker constructs a URL containing script payloads in the cols parameter and lures an authenticated Coda user into clicking it. The reflected payload executes in the victim's browser, inheriting the trust of the Coda origin. Additional technical details are documented in the Packet Storm advisory.

No verified proof-of-concept code is included here. Refer to the Packet Storm advisory for the disclosed payload structure.

Detection Methods for CVE-2024-28734

Indicators of Compromise

  • Web server or WAF logs containing GET requests to Coda endpoints with suspicious values in the cols parameter, such as HTML tags, javascript: schemes, or event handler attributes
  • Browser Content Security Policy (CSP) violation reports originating from Coda application pages
  • Unexpected outbound requests from authenticated Coda user sessions to attacker-controlled domains

Detection Strategies

  • Deploy web application firewall rules that inspect the cols query parameter for angle brackets, script tags, and encoded XSS payload signatures
  • Monitor referer and user-agent patterns to identify phishing-driven traffic funneling users into crafted Coda URLs
  • Correlate authentication events with anomalous DOM-modifying activity captured by browser telemetry or endpoint agents

Monitoring Recommendations

  • Enable verbose HTTP access logging on Coda web front-ends and forward logs to a centralized SIEM for query-parameter analysis
  • Alert on high-entropy or URL-encoded payloads in the cols parameter across historical logs to identify prior exploitation attempts
  • Track session anomalies such as concurrent logins, cookie reuse from new IPs, or unexpected financial transaction submissions

How to Mitigate CVE-2024-28734

Immediate Actions Required

  • Upgrade Unit4 Financials by Coda to release 2023Q4 or later, which addresses the reflected XSS in the cols parameter
  • Restrict access to the Coda web interface to trusted networks or VPN users where operationally feasible
  • Educate finance users about phishing links referencing internal Coda URLs and enforce reporting workflows for suspicious messages

Patch Information

Unit4 has resolved the vulnerability in Financials by Coda release 2023Q4. Administrators should consult the Unit4 Financial Management Software product page and contact Unit4 support for the appropriate upgrade package for their deployment. Post-upgrade, verify that the cols parameter is properly encoded in HTTP responses.

Workarounds

  • Configure the web application firewall or reverse proxy to block or sanitize requests containing script-like content in the cols parameter
  • Enforce a strict Content Security Policy that disables inline script execution to limit the impact of reflected payloads
  • Set HttpOnly and Secure flags on Coda session cookies to reduce the value of cookie theft via XSS
bash
# Example reverse-proxy rule (NGINX) to block obvious XSS payloads in the cols parameter
if ($arg_cols ~* "(<|%3c)\s*script|javascript:|onerror=|onload=") {
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.