First published: Fri Apr 07 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Snapcreek Ezp Coming Soon Page | <=1.0.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24398 is an authentication (admin+) stored Cross-Site Scripting (XSS) vulnerability in the Snap Creek Software EZP Coming Soon Page plugin version <= 1.0.7.3.
The Snap Creek Software EZP Coming Soon Page plugin version <= 1.0.7.3 is affected by CVE-2023-24398.
CVE-2023-24398 is classified as a medium severity vulnerability with a severity value of 4.8.
To fix CVE-2023-24398, update the Snap Creek Software EZP Coming Soon Page plugin to a version higher than 1.0.7.3.
The Common Weakness Enumeration (CWE) for CVE-2023-24398 is CWE-79, which is a category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').