CVE-2024-29114: WordPress Download Manager plugin <= 3.2.84 - Cross Site Scripting (XSS) vulnerability
Published Mar 19, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.
Affected Software
3 affected components
W3 Eden Download Manager<=3.2.84
WordPress Download Manager<=3.2.84
W3eden Download Manager Wordpress<3.2.85
Remediation
Information
Update to 3.2.85 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29114?
CVE-2024-29114 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2024-29114?
To fix CVE-2024-29114, update the W3 Eden Download Manager to version 3.2.85 or later.
3
What software is affected by CVE-2024-29114?
CVE-2024-29114 affects W3 Eden Download Manager versions up to 3.2.84.
4
Can CVE-2024-29114 lead to data breaches?
Yes, CVE-2024-29114 can allow attackers to execute malicious scripts, potentially leading to data breaches or other serious security issues.
5
Is there a patch for CVE-2024-29114?
Yes, a patch is available for CVE-2024-29114, which can be applied by updating your Download Manager software.