First published: Thu Oct 17 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gora Tech LLC Cooked Pro allows Stored XSS.This issue affects Cooked Pro: from n/a before 1.8.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cooked Pro | <1.8.0 | |
Cooked Pro | <1.8.0 |
Update to 1.8.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49289 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
To remediate CVE-2024-49289, update Cooked Pro to version 1.8.0 or later, which addresses the XSS vulnerability.
CVE-2024-49289 is an improper neutralization of input during web page generation vulnerability, specifically resulting in stored XSS.
CVE-2024-49289 affects all versions of Cooked Pro prior to 1.8.0.
Users of Gora Tech LLC Cooked Pro and WordPress Cooked Pro below version 1.8.0 are affected by CVE-2024-49289.