CVE-2024-29271: XSS
A reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.5 allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.
Other sources
Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29271?
CVE-2024-29271 has been classified as a high severity reflected Cross-Site Scripting vulnerability.
How do I fix CVE-2024-29271?
To fix CVE-2024-29271, upgrade VvvebJs to version 1.7.7 or later.
What software is impacted by CVE-2024-29271?
CVE-2024-29271 affects VvvebJs versions prior to 1.7.7.
What type of vulnerability is CVE-2024-29271?
CVE-2024-29271 is a reflected Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-29271 be exploited remotely?
Yes, CVE-2024-29271 can be exploited remotely by attackers through the action parameter in save.php.