Cross-Site Scripting Vulnerability in Dreamwinner Easy Language Switcher
CVE-2024-56029
7.1HIGH
What is CVE-2024-56029?
The vulnerability in Dreamwinner's Easy Language Switcher results from improper neutralization of input during web page generation, leading to a reflected cross-site scripting (XSS) issue. This allows attackers to inject malicious scripts into web pages viewed by users, potentially enabling unauthorized actions or data theft. The vulnerability impacts versions from n/a up to 1.0 of Easy Language Switcher, emphasizing the need for users to ensure their applications are updated and secured against such threats.
Affected Version(s)
Easy Language Switcher <= 1.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)