First published: Tue Jan 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Groundhogg Inc. Groundhogg allows Reflected XSS.This issue affects Groundhogg: from n/a through 3.7.3.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Groundhogg Hollerbox | <=3.7.3.3 | |
WordPress Groundhogg plugin | <=3.7.3.3 |
Update the WordPress Groundhogg wordpress plugin to the latest available version (at least 3.7.3.4).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56289 has been classified as a high severity vulnerability due to its potential impact on user data and security.
To fix CVE-2024-56289, it is recommended to update Groundhogg to version 3.7.3.4 or later.
CVE-2024-56289 is an Improper Neutralization of Input During Web Page Generation vulnerability, specifically a Reflected Cross-Site Scripting (XSS) issue.
CVE-2024-56289 affects all versions of Groundhogg up to and including version 3.7.3.3.
Users of Groundhogg, particularly those using versions 3.7.3.3 or earlier, are at risk from CVE-2024-56289.