First published: Tue Mar 19 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zaytech Smart Online Order for Clover allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through 1.5.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zaytech Smart Online Order for Clover | <1.5.6 | |
Clover Smart Online Order for Clover | <=1.5.5 | |
WordPress Smart Online Order for Clover | <=1.5.5 |
Update to 1.5.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29115 is classified as a stored Cross-site Scripting (XSS) vulnerability that may allow attackers to inject malicious scripts into web pages.
To remediate CVE-2024-29115, upgrade the Zaytech Smart Online Order for Clover plugin to version 1.5.6 or later.
CVE-2024-29115 affects Zaytech Smart Online Order for Clover from versions before 1.5.6 up to and including 1.5.5.
Users of the affected versions may be at risk of having their accounts compromised through stored XSS attacks.
Yes, CVE-2024-29115 can be exploited remotely by an attacker with access to the vulnerable web application.