Stored XSS Vulnerability in YayCommerce Brand Theme
CVE-2024-54348
6.5MEDIUM
Summary
CVE-2024-54348 is a high-risk vulnerability classified as Cross-site Scripting (XSS) within the YayCommerce Brand theme. This flaw allows attackers to inject malicious scripts into web pages, affecting users who view these pages. Specifically, the vulnerability occurs due to improper neutralization of input during the web page generation process. The affected versions include YayCommerce Brand Theme up to 1.1.6. As a result, users of this theme are urged to update to the latest version immediately to mitigate the risk of potential Stored XSS attacks, where the injected code can be saved and executed in the browsers of users accessing compromised pages.
Affected Version(s)
Brand <= 1.1.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
stealthcopter (Patchstack Alliance)