Reflected XSS Vulnerability in Enfold
CVE-2024-37199
7.1HIGH
What is CVE-2024-37199?
The Enfold Theme by Kriesi contains a vulnerability that allows for the execution of reflected cross-site scripting (XSS) attacks due to improper neutralization of input during web page generation. Attackers can exploit this flaw by injecting malicious scripts, which can lead to various impacts on affected users, including session hijacking and data theft. Users of Enfold Theme versions up to 5.6.9 should take immediate action to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Enfold <= 5.6.9