CVE-2024-25369: XSS
Published Feb 22, 2024
·Updated
A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the groupid parameter.
Affected Software
2 affected components
Fuel CMS Fuel CMS
TheDayLightStudio Fuel CMS=1.5.2
Event History
Feb 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25369?
The severity of CVE-2024-25369 is considered high due to its potential for reflected Cross-Site Scripting attacks.
2
How do I fix CVE-2024-25369?
To fix CVE-2024-25369, upgrade to the latest version of FUEL CMS where the vulnerability is patched.
3
What type of attack is associated with CVE-2024-25369?
CVE-2024-25369 is associated with reflected Cross-Site Scripting (XSS) attacks, allowing attackers to execute arbitrary code.
4
What is the affected software for CVE-2024-25369?
The affected software for CVE-2024-25369 is FUEL CMS version 1.5.2.
5
Can I exploit CVE-2024-25369 without authentication?
Yes, CVE-2024-25369 can be exploited without authentication, making it more accessible for attackers.