First published: Fri Dec 13 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Echoza allows Stored XSS.This issue affects Echoza: from n/a through 0.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Think201 | <=0.1.1 | |
WordPress | <=0.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54243 has a medium severity level due to its potential for Stored Cross-site Scripting (XSS) attacks.
CVE-2024-54243 allows attackers to inject malicious scripts into web pages viewed by other users, compromising their security.
To fix CVE-2024-54243, update Think201 Echoza to a version later than 0.1.1 that addresses the Stored XSS vulnerability.
Think201 Echoza versions from its initial release up to and including 0.1.1 are affected by CVE-2024-54243.
Yes, CVE-2024-54243 impacts WordPress Echoza versions up to and including 0.1.1, leading to similar security vulnerabilities.