White Label CMS vulnerable to Reflected XSS
CVE-2024-43303

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
18 August 2024

Summary

The vulnerability in White Label CMS allows for reflected Cross-Site Scripting (XSS) attacks due to improper neutralization of user input during the dynamic generation of web pages. This security flaw affects multiple versions of the CMS, posing risks to web applications that rely on this platform. Attackers can exploit this vulnerability to inject malicious scripts, leading to unauthorized actions being taken in the context of a user session, which could compromise user data and security.

Affected Version(s)

White Label CMS <= 2.7.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.