Cross-site Scripting Vulnerability in Adsmonetizer
CVE-2024-1437

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 February 2024

What is CVE-2024-1437?

The vulnerability affects the Adsmonetizer product developed by José Fernandez, specifically versions up to 3.1.2. It stems from improper neutralization of input during web page generation, leading to reflected cross-site scripting (XSS) attacks. This flaw can enable attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and session integrity. Taking preventive measures and applying patches are crucial to mitigate exposure to this threat.

Affected Version(s)

Adsmonetizer <= 3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Majed Refaea (Patchstack Alliance)
.