CVE-2024-25837: XSS
Published Aug 16, 2024
·Updated
A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.
Affected Software
2 affected components
October CMS Bloghub Plugin<=1.3.8
October CMS Debugbar<=1.3.8
Event History
Aug 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25837?
CVE-2024-25837 is classified as a medium severity vulnerability due to its potential for exploitation via injected scripts.
2
How do I fix CVE-2024-25837?
To fix CVE-2024-25837, update the October CMS Bloghub Plugin to version 1.3.9 or later.
3
What type of vulnerability is CVE-2024-25837?
CVE-2024-25837 is a stored cross-site scripting (XSS) vulnerability.
4
Which versions of the Bloghub Plugin are affected by CVE-2024-25837?
CVE-2024-25837 affects October CMS Bloghub Plugin versions 1.3.8 and lower.
5
What could an attacker do with CVE-2024-25837?
An attacker could execute arbitrary web scripts or HTML via a crafted payload in the Comments section.