CVE-2024-10103

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
Configurations

No configuration.

History

19 Nov 2024, 15:35

Type Values Removed Values Added
Summary
  • (es) En el proceso de prueba del complemento MailPoet para WordPress anterior a la versión 5.3.2, se encontró una vulnerabilidad que permite implementar XSS almacenado en nombre del editor mediante la incorporación de un script malicioso, lo que implica una puerta trasera de apropiación de cuentas.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

19 Nov 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-19 06:15

Updated : 2024-11-19 21:57


NVD link : CVE-2024-10103

Mitre link : CVE-2024-10103

CVE.ORG link : CVE-2024-10103


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')