First published: Wed Sep 18 2024(Updated: )
Welcart e-Commerce prior to 2.11.2 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Welcart Plugin | <2.11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45366 is classified as a cross-site scripting (XSS) vulnerability, which can lead to script execution in the user's web browser.
To fix CVE-2024-45366, upgrade to Welcart e-Commerce version 2.11.2 or later.
CVE-2024-45366 affects users of Welcart e-Commerce versions prior to 2.11.2.
If CVE-2024-45366 is exploited, an attacker may execute arbitrary scripts in the context of a user's web browser.
Yes, CVE-2024-45366 represents a remote attack vector that can be exploited by attackers through crafted web content.