CVE-2024-50803: XSS
Published Nov 19, 2024
·Updated
The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges
Affected Software
2 affected componentsFixes available
composer/redaxo/source<5.18.0
5.18.0
REDAXO REDAXO=5.17.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/redaxo/sourceto a version that resolves this vulnerability.Fixed in 5.18.0
Event History
Nov 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-50803?
CVE-2024-50803 has a high severity rating due to its potential for privilege escalation via Cross Site Scripting.
2
How do I fix CVE-2024-50803?
To mitigate CVE-2024-50803, upgrade the Redaxo Core CMS application to version 5.18.0 or higher.
3
What is the vulnerability type of CVE-2024-50803?
CVE-2024-50803 is classified as a Cross Site Scripting (XSS) vulnerability.
4
Which version of Redaxo is affected by CVE-2024-50803?
The affected version is Redaxo Core CMS application version 5.17.1.
5
Can CVE-2024-50803 be exploited remotely?
Yes, CVE-2024-50803 can be exploited remotely by an attacker to escalate privileges.