CVE-2024-21732: XSS
Published Jan 1, 2024
·Updated
FlyCms through abbaa5a allows XSS via the permission management feature.
Affected Software
1 affected component
Flycms Project Flycms<=2019-12-20
Event History
Jan 1, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-21732?
CVE-2024-21732 has been classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-21732?
To fix CVE-2024-21732, update FlyCms to a version released after December 20, 2019, that addresses the XSS vulnerability.
3
What type of vulnerability is CVE-2024-21732?
CVE-2024-21732 is an XSS (cross-site scripting) vulnerability affecting the permission management feature of FlyCms.
4
Who is affected by CVE-2024-21732?
Any user or organization using FlyCms version up to December 20, 2019, is affected by CVE-2024-21732.
5
Can CVE-2024-21732 be exploited by attackers?
Yes, CVE-2024-21732 can be exploited by attackers to execute malicious scripts in the context of users' browsers, compromising user data.