CVE-2024-45366: XSS
Published Sep 18, 2024
·Updated
Welcart e-Commerce prior to 2.11.2 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.
Affected Software
2 affected components
Welcart e-Commerce<2.11.2
Welcart Welcart e-Commerce WordPress<2.11.2
Event History
Sep 18, 2024
CVE Published
via MITRE·05:20 AM
Data Sourced
via MITRE·05:20 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45366?
CVE-2024-45366 is classified as a cross-site scripting (XSS) vulnerability, which can lead to script execution in the user's web browser.
2
How do I fix CVE-2024-45366?
To fix CVE-2024-45366, upgrade to Welcart e-Commerce version 2.11.2 or later.
3
Who is affected by CVE-2024-45366?
CVE-2024-45366 affects users of Welcart e-Commerce versions prior to 2.11.2.
4
What can happen if CVE-2024-45366 is exploited?
If CVE-2024-45366 is exploited, an attacker may execute arbitrary scripts in the context of a user's web browser.
5
Is CVE-2024-45366 a remote attack vector?
Yes, CVE-2024-45366 represents a remote attack vector that can be exploited by attackers through crafted web content.