Cross-Site Scripting Vulnerability in CF7 File Download by Rimes Gold
CVE-2024-33697

5.9MEDIUM

What is CVE-2024-33697?

The CF7 File Download plugin by Rimes Gold contains a vulnerability that allows for improper neutralization of input during web page generation, leading to Stored Cross-Site Scripting (XSS) attacks. This issue can enable attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user data and site integrity. The vulnerability affects versions n/a through 2.0, making it critical for users to apply patches as soon as possible to mitigate these risks.

Affected Version(s)

CF7 File Download – File Download for CF7 <= 2.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.