Cross-site Scripting Vulnerability in Geo Mashup by Dylan Kuhn
CVE-2024-44008

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2024

What is CVE-2024-44008?

The Geo Mashup plugin by Dylan Kuhn contains a vulnerability that allows for stored cross-site scripting (XSS) attacks due to improper input neutrality during web page generation. This can permit attackers to inject malicious scripts, which may be executed when users access affected pages. The issue impacts versions of Geo Mashup up to 1.13.12, highlighting the urgent need for users to apply security updates and protect their applications from potential exploits.

Affected Version(s)

Geo Mashup 0 <= 1.13.12

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.