First published: Wed Apr 24 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute info systems ARForms allows Reflected XSS.This issue affects ARForms: from n/a through 6.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Repute InfoSystems ARForms Form Builder | <=6.4 | |
ARForms Form Builder | <=6.4 |
Update to 6.4.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32702 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS).
To fix CVE-2024-32702, upgrade Repute InfoSystems ARForms to version 6.5 or later where the vulnerability has been addressed.
CVE-2024-32702 can result in unauthorized script execution on affected systems, leading to data theft or session hijacking.
CVE-2024-32702 affects users of Repute InfoSystems ARForms and WordPress ARForms versions up to 6.4.
Yes, CVE-2024-32702 is a known reflected XSS vulnerability in ARForms versions prior to 6.5.