CVE-2024-43985

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Bus Ticket Booking with Seat Reservation allows Stored XSS.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through 5.3.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mage-people:bus_ticket_booking_with_seat_reservation:*:*:*:*:*:wordpress:*:*

History

24 Sep 2024, 19:33

Type Values Removed Values Added
CPE cpe:2.3:a:mage-people:bus_ticket_booking_with_seat_reservation:*:*:*:*:*:wordpress:*:*
First Time Mage-people bus Ticket Booking With Seat Reservation
Mage-people
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : 4.8
References () https://patchstack.com/database/vulnerability/bus-ticket-booking-with-seat-reservation/wordpress-bus-ticket-booking-with-seat-reservation-plugin-5-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/bus-ticket-booking-with-seat-reservation/wordpress-bus-ticket-booking-with-seat-reservation-plugin-5-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve - Third Party Advisory

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en MagePeople Team Bus Ticket Booking with Seat Reservation permite XSS almacenado. Este problema afecta a la reserva de billetes de autobús con reserva de asiento: desde n/a hasta 5.3.5.

17 Sep 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-17 23:15

Updated : 2024-09-24 19:33


NVD link : CVE-2024-43985

Mitre link : CVE-2024-43985

CVE.ORG link : CVE-2024-43985


JSON object : View

Products Affected

mage-people

  • bus_ticket_booking_with_seat_reservation
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')