CVE-2024-43413: Xibo CMS XSS vulnerability using DataSet HTML columns
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute JavaScript via the DataSet functionality. Users can design a DataSet with a HTML column which contains JavaScript, which is intended functionality. The JavaScript gets executed on the Data Entry page and in any Layouts which reference it. This behavior has been changed in 4.1.0 to show HTML/CSS/JS as code on the Data Entry page. There are no workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43413?
CVE-2024-43413 is a cross-site scripting vulnerability that can significantly impact the integrity of the Xibo CMS.
How do I fix CVE-2024-43413?
To fix CVE-2024-43413, upgrade to Xibo CMS version 4.1.0 or later.
Who is affected by CVE-2024-43413?
All authorized users of Xibo CMS prior to version 4.1.0 are affected by CVE-2024-43413.
What type of vulnerability is CVE-2024-43413?
CVE-2024-43413 is classified as a cross-site scripting (XSS) vulnerability.
What can attackers do with CVE-2024-43413?
Attackers can exploit CVE-2024-43413 to execute arbitrary JavaScript code in the context of an authorized user's session.