CVE-2024-57556

Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component
References
Link Resource
https://github.com/nbubna/store/issues/127 Exploit Issue Tracking Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nbubna:store:*:*:*:*:*:*:*:*

History

05 Feb 2025, 17:44

Type Values Removed Values Added
References () https://github.com/nbubna/store/issues/127 - () https://github.com/nbubna/store/issues/127 - Exploit, Issue Tracking, Mitigation, Third Party Advisory
First Time Nbubna
Nbubna store
CPE cpe:2.3:a:nbubna:store:*:*:*:*:*:*:*:*

24 Jan 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
Summary
  • (es) La vulnerabilidad Cross Site Scripting en nbubna store v.2.14.2 y anteriores permite a un atacante remoto ejecutar código arbitrario a través del componente store.deep.js

23 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 22:15

Updated : 2025-02-05 17:44


NVD link : CVE-2024-57556

Mitre link : CVE-2024-57556

CVE.ORG link : CVE-2024-57556


JSON object : View

Products Affected

nbubna

  • store
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')