CVE-2024-33980: Cross-site Scripting in Janobe products
Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/modreports/printreport.php'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33980?
CVE-2024-33980 is classified as a medium severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-33980?
To fix CVE-2024-33980, ensure you apply the latest security patches provided by Janobe for version 1.0 of the affected products.
Which software versions are affected by CVE-2024-33980?
CVE-2024-33980 affects version 1.0 of Janobe's PayPal, Credit Card, and Debit Card Payment products.
What type of attack can be executed through CVE-2024-33980?
An attacker can exploit CVE-2024-33980 through Cross-Site Scripting (XSS) to obtain session cookie details from victims.
Is user intervention required to exploit CVE-2024-33980?
Yes, exploitation of CVE-2024-33980 requires the victim to click on a specially crafted URL.