First published: Tue Sep 17 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Kahuna allows Stored XSS.This issue affects Kahuna: from n/a through 1.7.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kahuna | <=1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43994 is categorized as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
To mitigate CVE-2024-43994, update Kahuna to a version later than 1.7.0 to eliminate the XSS vulnerability.
CVE-2024-43994 affects CryoutCreations Kahuna versions up to and including 1.7.0.
CVE-2024-43994 represents a stored XSS vulnerability where malicious scripts can be injected and stored within the web application.
It is highly discouraged to use Kahuna version 1.7.0 due to the presence of the CVE-2024-43994 vulnerability, as it poses significant security risks.