CVE-2024-37434: WordPress Atarim plugin <= 3.31 - Authenticated Cross Site Scripting (XSS) vulnerability
Published Jul 22, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim atarim-visual-collaboration.This issue affects Atarim: from n/a through <= 3.31.
Affected Software
1 affected component
Atarim Atarim Wordpress<3.32
Remediation
Information
Update to 3.32 or a higher version.
Event History
Jul 22, 2024
CVE Published
via MITRE·08:18 AM
Data Sourced
via MITRE·08:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37434?
CVE-2024-37434 has a medium severity rating as it allows for stored cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2024-37434?
To fix CVE-2024-37434, update Atarim to version 3.32 or later.
3
What systems are affected by CVE-2024-37434?
CVE-2024-37434 affects Atarim versions from n/a through 3.31.
4
What type of vulnerability is CVE-2024-37434?
CVE-2024-37434 is classified as an improper neutralization of input during web page generation, specifically an XSS vulnerability.
5
Can CVE-2024-37434 lead to data theft?
Yes, CVE-2024-37434 can potentially lead to data theft through stored XSS, allowing attackers to execute scripts in the context of the user.