CVE-2024-43992: WordPress LatePoint plugin <= 4.9.91 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Latepoint LatePoint allows Stored XSS.This issue affects LatePoint: from n/a through 4.9.91.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43992?
CVE-2024-43992 has a medium severity rating due to its potential for resulting in stored cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2024-43992?
To fix CVE-2024-43992, update to the latest version of LatePoint that is patched for this vulnerability.
What versions of LatePoint are affected by CVE-2024-43992?
CVE-2024-43992 affects LatePoint versions up to and including 4.9.91.
What types of attacks can CVE-2024-43992 facilitate?
CVE-2024-43992 can facilitate stored cross-site scripting (XSS) attacks, allowing attackers to execute scripts in the context of other users' browsers.
Is user data at risk due to CVE-2024-43992?
Yes, CVE-2024-43992 can put user data at risk as it allows attackers to inject malicious scripts that could access sensitive information.