First published: Fri Dec 13 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Easy Replace allows Stored XSS.This issue affects Easy Replace: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Think201 | <=1.3 | |
WordPress Easy Replace | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54244 has a medium severity rating due to its impact on web application security through stored cross-site scripting.
To fix CVE-2024-54244, update Think201 Easy Replace to version 1.4 or later.
CVE-2024-54244 is caused by improper neutralization of input during web page generation which allows stored cross-site scripting attacks.
Users of Think201 Easy Replace versions up to and including 1.3 are affected by CVE-2024-54244.
CVE-2024-54244 is not classified as a zero-day vulnerability, but it should be addressed promptly to mitigate risks.