First published: Thu Dec 14 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Plugin-planet Dashboard Widget Suite | <3.4.2 |
Update to 3.4.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49743 has a high severity due to the potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2023-49743, upgrade Dashboard Widgets Suite to version 3.4.2 or later.
CVE-2023-49743 allows for stored XSS attacks, which can compromise user sessions and sensitive information.
CVE-2023-49743 affects Dashboard Widgets Suite versions up to and including 3.4.1.
Yes, if you are using an affected version of Dashboard Widgets Suite, your website is at risk of exploitation via stored XSS.