Stored XSS Vulnerability in Brainstorm Force Astra Widgets
CVE-2024-56274
6.5MEDIUM
Key Information:
- Vendor
- Brainstorm Force
- Status
- Astra Widgets
- Vendor
- CVE Published:
- 7 January 2025
Summary
A stored cross-site scripting (XSS) vulnerability has been discovered in the Astra Widgets plugin by Brainstorm Force. This flaw allows an attacker to inject malicious scripts into web pages viewed by users. The vulnerability affects users by enabling the execution of harmful scripts stored on the server, posing a significant risk to user data and privacy. Impacted versions include Astra Widgets from n/a up to 1.2.15. It is essential for users of affected versions to apply security patches promptly to mitigate potential exploits.
Affected Version(s)
Astra Widgets <= 1.2.15
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)