First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Conversios Conversios.Io allows Reflected XSS.This issue affects Conversios.Io: from n/a through 6.9.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Conversios | <=6.9.1 | |
WordPress Conversios.io plugin | <=6.9.1 |
Update to 7.0.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29794 is classified as a medium severity reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2024-29794, upgrade Conversios.Io or the WordPress Conversios.io plugin to the latest version beyond 6.9.1.
CVE-2024-29794 affects Conversios.Io up to version 6.9.1 and the WordPress Conversios.io plugin also up to version 6.9.1.
CVE-2024-29794 is a reflected cross-site scripting (XSS) vulnerability.
CVE-2024-29794 allows an attacker to execute arbitrary JavaScript in the context of the affected web page.