First published: Wed May 08 2024(Updated: )
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34255 has been classified as a high severity Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2024-34255, update jizhicms to the latest version that addresses this vulnerability.
CVE-2024-34255 can allow attackers to execute malicious scripts in the context of users visiting vulnerable pages.
CVE-2024-34255 affects jizhicms v2.5.1 and potentially earlier versions.
A temporary workaround for CVE-2024-34255 is to sanitize user input in the message function to prevent script injection.