CVE-2024-53620: XSS
Published Nov 26, 2024
·Updated
A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.
Affected Software
2 affected components
Spip Article module
Spip SPIP=4.3.3
Event History
Nov 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53620?
CVE-2024-53620 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2024-53620?
To fix CVE-2024-53620, update the SPIP Article module to a version that addresses this vulnerability.
3
Who is affected by CVE-2024-53620?
Authenticated users of SPIP v4.3.3 with the Article module are affected by CVE-2024-53620.
4
What is the impact of CVE-2024-53620?
CVE-2024-53620 allows authenticated attackers to execute arbitrary web scripts or HTML, leading to potential account compromise.
5
When was CVE-2024-53620 disclosed?
CVE-2024-53620 was disclosed in an advisory on the specific vulnerability affecting SPIP v4.3.3.