CVE-2024-25381: XSS
Published Feb 21, 2024
·Updated
There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.
Affected Software
2 affected components
Emlog Emlog Pro
Emlog emlog=2.2.8
Event History
Feb 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25381?
CVE-2024-25381 is classified as a medium severity vulnerability due to its potential for exploitation through stored XSS attacks.
2
How do I fix CVE-2024-25381?
To mitigate CVE-2024-25381, you should update Emlog Pro to the latest version where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2024-25381?
CVE-2024-25381 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2024-25381?
CVE-2024-25381 affects users of Emlog Pro version 2.2.8.
5
What can an attacker do with CVE-2024-25381?
An attacker can exploit CVE-2024-25381 to inject malicious scripts that can steal user data or perform actions on behalf of users.