White Label CMS vulnerable to Reflected XSS
CVE-2024-43303
7.1HIGH
Summary
The vulnerability in White Label CMS allows for reflected Cross-Site Scripting (XSS) attacks due to improper neutralization of user input during the dynamic generation of web pages. This security flaw affects multiple versions of the CMS, posing risks to web applications that rely on this platform. Attackers can exploit this vulnerability to inject malicious scripts, leading to unauthorized actions being taken in the context of a user session, which could compromise user data and security.
Affected Version(s)
White Label CMS <= 2.7.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)