CVE-2024-12723: Infility Global <= 2.9.8 - Reflected XSS
The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12723?
CVE-2024-12723 has a high severity due to its potential impact on high privilege users such as admin through Reflected Cross-Site Scripting.
How do I fix CVE-2024-12723?
To fix CVE-2024-12723, update the Infility Global WordPress plugin to version 2.9.9 or later where the issue has been addressed.
What types of users are affected by CVE-2024-12723?
CVE-2024-12723 primarily affects high privilege users, including admin accounts on affected WordPress sites.
Does CVE-2024-12723 affect older versions of the Infility Global WordPress plugin?
Yes, CVE-2024-12723 affects all versions of the Infility Global WordPress plugin up to and including 2.9.8.
Can CVE-2024-12723 lead to data compromise?
Yes, CVE-2024-12723 could potentially lead to data compromise by allowing attackers to execute malicious scripts on the web application.