CVE-2024-21504: XSS
Published Mar 19, 2024
·Updated
Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it.
Affected Software
2 affected componentsFixes available
composer/livewire/livewire>=3.3.5<3.4.9
3.4.9
Laravel Livewire>=3.3.5<=3.4.9
Remediation
Patch Available
Event History
Mar 19, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
RemedyAffected Software
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-21504?
CVE-2024-21504 is classified as a high severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-21504?
To fix CVE-2024-21504, upgrade the livewire/livewire package to version 3.4.9 or later.
3
What versions are affected by CVE-2024-21504?
CVE-2024-21504 affects livewire/livewire versions from 3.3.5 to 3.4.8.
4
What type of vulnerability is CVE-2024-21504?
CVE-2024-21504 is a Cross-site Scripting (XSS) vulnerability.
5
What can attackers do with CVE-2024-21504?
Attackers can inject malicious HTML code in the context of a user's browser session via crafted links.