CVE-2024-35498: XSS
Published Jan 6, 2025
·Updated
A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
2 affected components
composer/getgrav/grav<=1.7.45
getgrav Grav=1.7.45
Event History
Jan 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-35498?
CVE-2024-35498 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-35498?
To fix CVE-2024-35498, upgrade to Grav version later than 1.7.45 that addresses this cross-site scripting issue.
3
Who is affected by CVE-2024-35498?
CVE-2024-35498 affects users running Grav version 1.7.45.
4
What type of vulnerability is CVE-2024-35498?
CVE-2024-35498 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-35498 lead to data theft?
Yes, CVE-2024-35498 can allow attackers to execute arbitrary web scripts, potentially leading to data theft.