Cross-site Scripting Vulnerability in Arconix Shortcodes by Tyche Softwares
CVE-2024-56242
5.4MEDIUM
What is CVE-2024-56242?
The vulnerability stems from improper neutralization of input during the generation of web pages within Arconix Shortcodes by Tyche Softwares. This flaw allows an attacker to exploit stored Cross-site Scripting (XSS) vulnerabilities, potentially leading to unauthorized access to user data and session hijacking. The affected versions include all preceding 2.1.14, enabling malicious scripts to be persisted within webpage content.
Affected Version(s)
Arconix Shortcodes <= 2.1.14