CVE-2024-38696: WordPress Zoho CRM Lead Magnet plugin <= 1.7.8.8 - Cross Site Scripting (XSS) vulnerability
Published Jul 20, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows Reflected XSS.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.8.8.
Affected Software
2 affected components
Zoho CRM Lead Magnet>=n/a<1.7.8.8
WordPress Zoho CRM Lead Magnet plugin<=1.7.8.8
Remediation
Information
Update to 1.7.8.9 or a higher version.
Event History
Jul 20, 2024
CVE Published
via MITRE·07:35 AM
Data Sourced
via MITRE·07:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38696?
CVE-2024-38696 has a moderate severity level due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-38696?
To fix CVE-2024-38696, update the Zoho CRM Lead Magnet to a version higher than 1.7.8.8.
3
What software is affected by CVE-2024-38696?
CVE-2024-38696 affects Zoho CRM Lead Magnet and WordPress Zoho CRM Lead Magnet plugin versions up to and including 1.7.8.8.
4
What type of vulnerability is CVE-2024-38696?
CVE-2024-38696 is classified as a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-38696 be exploited remotely?
Yes, CVE-2024-38696 can be exploited remotely by sending specially crafted requests that trigger the XSS.