First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
wp-property-hive PropertyHive WordPress | <2.0.9 | |
WordPress PropertyHive | <=2.0.8 | |
WordPress PropertyHive | <=2.0.8 |
Update to 2.0.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29923 is classified as a high severity reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2024-29923, upgrade PropertyHive to version 2.0.9 or later.
CVE-2024-29923 affects PropertyHive versions from n/a through 2.0.8.
CVE-2024-29923 can lead to reflected cross-site scripting (XSS) attacks, which may allow attackers to execute arbitrary scripts in the victim's browser.
Users and administrators of PropertyHive versions 2.0.8 and earlier on WordPress are impacted by CVE-2024-29923.