First published: Thu Mar 21 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Data443 Tracking Code Manager | <=2.0.16 | |
WordPress Tracking Code Manager | <=2.0.16 |
Update to 2.1.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2579 is a critical vulnerability that allows attackers to exploit cross-site scripting (XSS) in affected versions of Data443 Tracking Code Manager.
To fix CVE-2024-2579, update Data443 Tracking Code Manager to version 2.0.17 or later.
CVE-2024-2579 affects all versions of Data443 Tracking Code Manager up to and including version 2.0.16.
CVE-2024-2579 can be exploited by injecting malicious scripts into web pages that are rendered to users, allowing attackers to steal session cookies or perform actions on behalf of users.
Yes, CVE-2024-2579 specifically affects both Data443 Tracking Code Manager and WordPress Tracking Code Manager versions up to 2.0.16.