CVE-2024-26484: XSS
A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this issue did not affect any version of Kirby CMS. The only effect was on the trykirby.com demo site, which is not customer-controlled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26484?
CVE-2024-26484 is classified as a stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-26484?
To mitigate CVE-2024-26484, ensure that the Edit Content Layout module is properly sanitized and updated to the latest version provided by the vendor.
Which versions of Kirby CMS are affected by CVE-2024-26484?
CVE-2024-26484 specifically affects Kirby CMS v4.1.0.
Can CVE-2024-26484 allow attackers to take control of my website?
Yes, if exploited, CVE-2024-26484 can allow attackers to execute arbitrary web scripts or HTML on your site.
What is the nature of the attack vector in CVE-2024-26484?
CVE-2024-26484 allows attackers to inject crafted payloads into the Link field, exploiting stored XSS.