Stored XSS Vulnerability in Brainstorm Force Astra Widgets
CVE-2024-56274

6.5MEDIUM

Key Information:

Vendor
Brainstorm Force
Status
Astra Widgets
Vendor
CVE Published:
7 January 2025

Summary

A stored cross-site scripting (XSS) vulnerability has been discovered in the Astra Widgets plugin by Brainstorm Force. This flaw allows an attacker to inject malicious scripts into web pages viewed by users. The vulnerability affects users by enabling the execution of harmful scripts stored on the server, posing a significant risk to user data and privacy. Impacted versions include Astra Widgets from n/a up to 1.2.15. It is essential for users of affected versions to apply security patches promptly to mitigate potential exploits.

Affected Version(s)

Astra Widgets <= 1.2.15

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.