Reflected XSS Vulnerability in CopySafe Web Protection
CVE-2024-38781

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 July 2024

What is CVE-2024-38781?

A Cross-site Scripting (XSS) vulnerability exists in ArtistScope CopySafe Web Protection, allowing attackers to execute arbitrary scripts on the client side by injecting malicious code into a web page. This flaw affects versions up to 3.15 and enables reflected XSS attacks, potentially compromising user data and site integrity. Organizations using this product should take immediate action to mitigate this security risk by implementing necessary patches and reviewing their web application security practices.

Affected Version(s)

CopySafe Web Protection <= 3.15

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.