First published: Tue Nov 19 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <=3.8.16 | |
Ninja Forms | <=3.8.16 | |
Ninja Forms | <=3.8.16 |
Update to 3.8.18 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50515 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2024-50515, update Ninja Forms to version 3.8.17 or later.
CVE-2024-50515 affects Ninja Forms versions up to and including 3.8.16.
CVE-2024-50515 can lead to stored cross-site scripting attacks that could compromise user information.
Users of Ninja Forms prior to version 3.8.17 are impacted by CVE-2024-50515.