CVE-2024-37920: WordPress ARForms Form Builder plugin <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jul 20, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Repute InfoSystems ARForms Form Builder allows Reflected XSS.This issue affects ARForms Form Builder: from n/a through 1.6.7.
Affected Software
3 affected components
Repute InfoSystems ARForms Form Builder<=1.6.7
WordPress ARForms Form Builder<=1.6.7
reputeinfosystems Arforms Form Builder Wordpress<1.6.8
Remediation
Information
Update to 1.6.8 or a higher version.
Event History
Jul 20, 2024
CVE Published
via MITRE·08:58 AM
Data Sourced
via MITRE·08:58 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37920?
CVE-2024-37920 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-37920?
To fix CVE-2024-37920, update Repute InfoSystems ARForms Form Builder to version 1.6.8 or later.
3
What software is affected by CVE-2024-37920?
CVE-2024-37920 affects Repute InfoSystems ARForms Form Builder versions up to and including 1.6.7.
4
What type of vulnerability is CVE-2024-37920?
CVE-2024-37920 is an improper neutralization of input during web page generation, allowing for reflected XSS attacks.
5
Can CVE-2024-37920 be exploited remotely?
Yes, CVE-2024-37920 can be exploited remotely, allowing attackers to execute harmful scripts in users' browsers.