First published: Thu Oct 17 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NinjaTeam Click to Chat – WP Support All-in-One Floating Widget allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through 2.3.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NinjaTeam Click to Chat – WP Support All-in-One Floating Widget | <2.3.4 | |
Ninja Team Click to Chat – WP Support All-in-One Floating Widget | <=2.3.3 | |
NinjaTeam Click to Chat – WP Support All-in-One Floating Widget | <=2.3.3 |
Update to 2.3.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49281 is rated as a high severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS).
To fix CVE-2024-49281, update the NinjaTeam Click to Chat – WP Support All-in-One Floating Widget to version 2.3.4 or later.
CVE-2024-49281 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as XSS.
CVE-2024-49281 affects versions of NinjaTeam Click to Chat – WP Support All-in-One Floating Widget up to and including 2.3.3.
The impact of CVE-2024-49281 allows attackers to execute arbitrary scripts in the context of affected users, potentially compromising session data and credentials.