CVE-2024-45933

OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.
Configurations

No configuration.

History

08 Oct 2024, 19:35

Type Values Removed Values Added
CWE CWE-94
Summary
  • (es) OnlineNewsSite v1.0 es vulnerable a Cross Site Scripting (XSS) que permite a los atacantes ejecutar código arbitrario a través de los campos Título y Resumen en el endpoint /admin/post/edit/.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.6

07 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-07 15:15

Updated : 2024-10-08 19:35


NVD link : CVE-2024-45933

Mitre link : CVE-2024-45933

CVE.ORG link : CVE-2024-45933


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')