Cross-site Scripting Vulnerability in LGPD Framework
CVE-2024-52465
7.1HIGH
What is CVE-2024-52465?
The Data443 LGPD Framework is affected by a vulnerability that allows reflected cross-site scripting (XSS) due to improper neutralization of input during web page generation. This vulnerability permits attackers to inject arbitrary scripts into responses, which can be executed in the context of the user's browser. Users interacting with a compromised version may inadvertently expose sensitive data and experience unauthorized actions. The issue impacts all versions from 'n/a' through 2.0.2, necessitating immediate attention for remediation.
Affected Version(s)
LGPD Framework <= 2.0.2