CVE-2024-24389: XSS
Published Mar 7, 2024
·Updated
A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Column Name parameter.
Affected Software
2 affected components
XunRui XunRuiCMS<=4.6.2
Xunruicms Xunruicms<=4.6.2
Event History
Mar 7, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24389?
CVE-2024-24389 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-24389?
To fix CVE-2024-24389, upgrade XunRuiCMS to version 4.6.3 or later.
3
What versions of XunRuiCMS are affected by CVE-2024-24389?
CVE-2024-24389 affects XunRuiCMS versions up to and including 4.6.2.
4
What could an attacker achieve by exploiting CVE-2024-24389?
An attacker can execute arbitrary web scripts or HTML by injecting a crafted payload into the Add Column Name parameter.
5
Is CVE-2024-24389 a permanent issue in XunRuiCMS?
No, CVE-2024-24389 is not a permanent issue as it can be resolved by updating to a patched version.