Reflected XSS Vulnerability in DirectoryPress by Designinvento
CVE-2024-49633
7.1HIGH
What is CVE-2024-49633?
The DirectoryPress plugin developed by Designinvento is prone to a reflected cross-site scripting (XSS) vulnerability. When user input is not properly sanitized during web page generation, attackers can exploit this flaw to inject malicious scripts into the web pages served by DirectoryPress. This vulnerability affects all versions from its inception up to 3.6.19, potentially allowing unauthorized actions to be performed by users, leading to compromised sessions or data exposure. It is crucial for website owners using DirectoryPress to apply updates and implement robust security measures to mitigate the risk associated with this vulnerability.
Affected Version(s)
DirectoryPress 0 <= 3.6.19