First published: Wed Sep 04 2024(Updated: )
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | <=2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44818 is considered a medium severity vulnerability due to its potential to expose sensitive information through cross-site scripting.
To fix CVE-2024-44818, update your ZZCMS version to one released after 2023, ensuring that input validation and output encoding are properly implemented.
CVE-2024-44818 affects all versions of ZZCMS up to and including version 2023.
The impact of CVE-2024-44818 allows remote attackers to conduct cross-site scripting attacks and potentially access sensitive information.
A potential workaround for CVE-2024-44818 includes filtering or sanitizing the HTTP_Referer header to mitigate the risk of cross-site scripting.