First published: Tue Nov 19 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel J Griffiths Beacon For Help Scout allows DOM-Based XSS.This issue affects Beacon For Help Scout: from n/a through 1.3.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Beacon For Help Scout | <=1.3.0 | |
WordPress Beacon For Help Scout | <=1.3.0 |
Deactivate and delete.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51828 has a critical severity rating due to its potential for DOM-Based Cross-site Scripting (XSS).
To fix CVE-2024-51828, update the Beacon For Help Scout to version 1.3.1 or later, where the vulnerability is addressed.
CVE-2024-51828 affects Beacon For Help Scout versions up to and including 1.3.0.
CVE-2024-51828 is classified as an Improper Neutralization of Input During Web Page Generation leading to Cross-site Scripting (XSS).
Yes, CVE-2024-51828 can be exploited remotely by attackers leveraging the XSS vulnerability.