CVE-2024-33981: Cross-site Scripting in Janobe products
Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/modreports/index.php'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33981?
CVE-2024-33981 has a high severity due to its potential to exploit Cross-Site Scripting vulnerabilities.
How do I fix CVE-2024-33981?
To fix CVE-2024-33981, you should upgrade to the patched version of the Janobe products that have addressed this vulnerability.
Which versions are affected by CVE-2024-33981?
CVE-2024-33981 affects version 1.0 of Janobe Credit Card, Debit Card Payment, and PayPal products.
What are the potential impacts of CVE-2024-33981?
The potential impacts of CVE-2024-33981 include session hijacking and unauthorized access to sensitive user information.
Who is affected by CVE-2024-33981?
Users of Janobe Credit Card, Debit Card Payment, and PayPal version 1.0 are affected by CVE-2024-33981.