CVE-2024-30953: XSS
A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link Name parameter of Menu Editor module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30953?
CVE-2024-30953 is categorized as a critical stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-30953?
To fix CVE-2024-30953, it is recommended to update Htmly to the latest version that addresses this XSS vulnerability.
What impact does CVE-2024-30953 have on Htmly software?
CVE-2024-30953 allows attackers to execute arbitrary web scripts or HTML, potentially compromising users' data and session integrity.
Who is affected by CVE-2024-30953?
Any user or administrator of Htmly v2.9.5 is potentially affected by CVE-2024-30953 if they utilize the Menu Editor module.
How is CVE-2024-30953 exploited?
CVE-2024-30953 is exploited through a crafted payload injected into the Link Name parameter of the Menu Editor.