CVE-2024-57041: XSS
Published Jan 24, 2025
·Updated
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
Affected Software
3 affected componentsFixes available
npm/nodebb<3.11.1
3.11.1
nodebb Nodebb
nodebb Nodebb=3.11.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/nodebbto a version that resolves this vulnerability.Fixed in 3.11.1
Event History
Jan 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyAffected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-57041?
CVE-2024-57041 is categorized as a persistent cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-57041?
To fix CVE-2024-57041, upgrade NodeBB to version 3.11.1 or later.
3
What versions of NodeBB are affected by CVE-2024-57041?
NodeBB version 3.11.0 is affected by CVE-2024-57041.
4
What is the impact of CVE-2024-57041?
CVE-2024-57041 allows remote attackers to store arbitrary code in a user's profile, potentially compromising user accounts.
5
Who is impacted by CVE-2024-57041?
Users of NodeBB version 3.11.0 are impacted by CVE-2024-57041, as it allows potential exploitation through user profiles.