Cross-Site Scripting Vulnerability in AJAX Login and Registration Modal Popup by Maxim K
CVE-2024-33918

5.9MEDIUM

What is CVE-2024-33918?

A security flaw has been identified in the AJAX Login and Registration modal popup + inline form developed by Maxim K. This vulnerability allows for improper neutralization of input during web page generation, leading to Stored Cross-Site Scripting (XSS) attacks. An attacker could exploit this weakness by injecting malicious scripts into areas where user input is processed, potentially compromising the security of user data and enabling unauthorized actions within the application.

Affected Version(s)

AJAX Login and Registration modal popup + inline form <= 2.23

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.