CVE-2024-46410: XSS
Published Oct 8, 2024
·Updated
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature
Affected Software
2 affected components
PublicCMS publiccms
PublicCMS publiccms=4.0.202406.e
Event History
Oct 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46410?
CVE-2024-46410 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-46410?
To fix CVE-2024-46410, ensure that input validation and output encoding are properly implemented in the Category Management feature.
3
What software is affected by CVE-2024-46410?
CVE-2024-46410 affects PublicCMS version 4.0.202406.e and earlier versions.
4
What impact does CVE-2024-46410 have on users?
CVE-2024-46410 could allow attackers to execute arbitrary scripts in the context of authenticated users, potentially compromising user accounts.
5
Is there a patch available for CVE-2024-46410?
As of now, no official patch has been released for CVE-2024-46410, so applying secure coding practices is recommended.