A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
References
Configurations
No configuration.
History
06 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
Summary |
|
|
CWE | CWE-79 |
24 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-24 20:15
Updated : 2025-02-06 22:15
NVD link : CVE-2024-57041
Mitre link : CVE-2024-57041
CVE.ORG link : CVE-2024-57041
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')