CVE-2024-11971: Guizhou Xiaoma Technology jpress Avatar upload cross site scripting
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11971?
CVE-2024-11971 is classified as problematic, indicating a significant security risk.
How do I fix CVE-2024-11971?
To fix CVE-2024-11971, update Guizhou Xiaoma Technology jpress to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2024-11971?
CVE-2024-11971 is a cross-site scripting (XSS) vulnerability affecting the Avatar Handler component.
Which version of jpress is affected by CVE-2024-11971?
CVE-2024-11971 affects Guizhou Xiaoma Technology jpress version 5.1.2.
What component is impacted by CVE-2024-11971?
CVE-2024-11971 impacts the Avatar Handler component, specifically the file /commons/attachment/upload.