First published: Sun Sep 15 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Parabola allows Stored XSS.This issue affects Parabola: from n/a through 2.4.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Parabola | <=2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44058 is categorized as a high severity vulnerability due to its potential for enabling stored cross-site scripting (XSS) attacks.
To fix CVE-2024-44058, users should update their CryoutCreations Parabola theme to the latest version that addresses this vulnerability.
CVE-2024-44058 affects the CryoutCreations Parabola theme from its initial release up to and including version 2.4.1.
Yes, CVE-2024-44058 can lead to data theft as it enables attackers to execute malicious scripts in the context of user sessions.
Stored XSS, as related to CVE-2024-44058, occurs when an attacker is able to store malicious scripts on the server, which are then delivered to users who visit affected pages.