CVE-2024-51577: WordPress bpmn.io plugin <= 1.0 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in neville.lugton bpmn.io bpmnio allows Stored XSS.This issue affects bpmn.io: from n/a through <= 1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51577?
CVE-2024-51577 has been classified as a medium severity vulnerability due to its potential for Stored Cross-site Scripting (XSS).
How do I fix CVE-2024-51577?
To fix CVE-2024-51577, update the bpmn.io plugin to the latest version that addresses the XSS vulnerability.
What impact does CVE-2024-51577 have on my application?
CVE-2024-51577 allows an attacker to execute arbitrary scripts in the context of users' browsers, potentially compromising user data.
Which software versions are affected by CVE-2024-51577?
CVE-2024-51577 affects bpmn.io version 1.0 and earlier versions.
Is CVE-2024-51577 exploitably easy for attackers?
Yes, CVE-2024-51577 can be exploited easily if an attacker manages to inject malicious scripts into the vulnerable application.