First published: Thu Jul 04 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xtendify Woffice | <5.4.9 |
Update to 5.4.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37471 is classified as a Cross Site Scripting (XSS) vulnerability that can allow attackers to execute malicious scripts on the affected system.
To fix CVE-2024-37471, it is recommended to update Woffice Core to version 5.4.9 or later.
CVE-2024-37471 affects all versions of Woffice Core from n/a up to and including 5.4.8.
CVE-2024-37471 can enable reflected XSS attacks, potentially compromising user sessions and sensitive information.
Website administrators using the affected Woffice Core version are responsible for addressing CVE-2024-37471 by applying the necessary updates.