CVE-2024-41453: XSS
Published Jan 15, 2025
·Updated
A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
Affected Software
1 affected component
ProcessMaker pm4core-docker
Event History
Jan 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-41453?
CVE-2024-41453 is classified as a critical severity vulnerability due to its potential for executing arbitrary scripts.
2
How do I fix CVE-2024-41453?
To fix CVE-2024-41453, update Process Maker pm4core-docker to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2024-41453?
CVE-2024-41453 affects Process Maker pm4core-docker version 4.1.21-RC7.
4
What type of vulnerability is CVE-2024-41453?
CVE-2024-41453 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-41453 lead to data breaches?
Yes, CVE-2024-41453 can allow attackers to execute scripts that may lead to data breaches or unauthorized access.