CVE-2024-43238: WordPress weMail plugin <= 1.14.5 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows DOM-Based XSS.This issue affects weMail: from n/a through <= 1.14.5.
Affected Software
1 affected component
weDevs Wemail Wordpress<1.14.6
Remediation
Information
Update to 1.14.6 or a higher version.
Event History
Aug 18, 2024
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 17, 58279
Event
via MITRE·12:20 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-43238?
CVE-2024-43238 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
2
How does CVE-2024-43238 affect weMail?
CVE-2024-43238 allows attackers to execute arbitrary JavaScript in the context of the user's browser when weMail generates a web page.
3
How can I fix CVE-2024-43238?
To mitigate CVE-2024-43238, upgrade weMail to version 1.14.6 or later.
4
What versions of weMail are affected by CVE-2024-43238?
CVE-2024-43238 affects all weMail versions prior to 1.14.6.
5
What is Cross-site Scripting (XSS) in the context of CVE-2024-43238?
Cross-site Scripting (XSS) in CVE-2024-43238 refers to the vulnerability that allows the injection of malicious scripts into web pages served to users.