CVE-2024-34243: XSS
Published May 14, 2024
·Updated
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
Affected Software
2 affected components
npm/kongadmin<=0.14.9
Pantsel Konga=0.14.9
Event History
May 14, 2024
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
Description
Data Sourced
via NVD·04:17 PM
Description
Data Sourced
via NVD·04:17 PM
SeverityWeakness
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-34243?
CVE-2024-34243 is a high severity Cross Site Scripting (XSS) vulnerability affecting Konga version 0.14.9.
2
How do I fix CVE-2024-34243?
To fix CVE-2024-34243, upgrade Konga to a version later than 0.14.9 which addresses this XSS vulnerability.
3
Which versions of Konga are affected by CVE-2024-34243?
Konga version 0.14.9 is the only version affected by CVE-2024-34243.
4
What threat does CVE-2024-34243 pose?
CVE-2024-34243 allows attackers to perform Cross Site Scripting (XSS) attacks, potentially compromising user data and session integrity.
5
Is there a workaround for CVE-2024-34243?
There is no known workaround for CVE-2024-34243; the recommended action is to upgrade to a secure version.