First published: Mon Aug 12 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CreativeMinds Solutions CM Tooltip Glossary | <=4.3.7 | |
WordPress CM Tooltip Glossary Plugin | <=4.3.7 |
Update to 4.3.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43149 is classified as a moderate severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
To mitigate CVE-2024-43149, update the CM Tooltip Glossary plugin to version 4.3.8 or later.
CVE-2024-43149 allows an attacker to exploit stored cross-site scripting (XSS) by injecting malicious scripts into web pages.
CVE-2024-43149 affects all versions of CM Tooltip Glossary from n/a through 4.3.7.
While removing the CM Tooltip Glossary plugin will prevent CVE-2024-43149, it may also remove essential functionality from your site.