Reflected XSS Vulnerability in DirectoryPress by Designinvento
CVE-2024-49633
What is CVE-2024-49633?
The DirectoryPress plugin developed by Designinvento is prone to a reflected cross-site scripting (XSS) vulnerability. When user input is not properly sanitized during web page generation, attackers can exploit this flaw to inject malicious scripts into the web pages served by DirectoryPress. This vulnerability affects all versions from its inception up to 3.6.19, potentially allowing unauthorized actions to be performed by users, leading to compromised sessions or data exposure. It is crucial for website owners using DirectoryPress to apply updates and implement robust security measures to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DirectoryPress <= 3.6.19
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved