First published: Tue Jul 09 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Cross-Site Scripting (XSS), Stored XSS.This issue affects Elementor Website Builder: from n/a through 3.22.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Website Builder | <3.22.2 |
Update to 3.22.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37437 has a high severity due to its potential to allow Cross-Site Scripting (XSS) attacks.
To fix CVE-2024-37437, update Elementor Website Builder to version 3.22.2 or later.
CVE-2024-37437 affects Elementor Website Builder from versions prior to 3.22.2.
CVE-2024-37437 is a Path Traversal vulnerability that can lead to XSS attacks.
Yes, CVE-2024-37437 can enable attackers to execute stored XSS, potentially leading to data breaches.