CVE-2024-29271

Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.
Configurations

No configuration.

History

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://github.com/givanz/VvvebJs/commit/c0c0545b44b23acc288ef907fb498ce15b9b576e - () https://github.com/givanz/VvvebJs/commit/c0c0545b44b23acc288ef907fb498ce15b9b576e -
References () https://github.com/givanz/VvvebJs/issues/342 - () https://github.com/givanz/VvvebJs/issues/342 -

28 Aug 2024, 14:35

Type Values Removed Values Added
CWE CWE-79
Summary
  • (es) Vulnerabilidad reflejada de cross-site scripting (XSS) en VvvebJs anteriores a la versión 1.7.7, permite a atacantes remotos ejecutar código arbitrario y obtener información confidencial a través del parámetro de acción en save.php.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

22 Mar 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-22 04:15

Updated : 2024-11-21 09:07


NVD link : CVE-2024-29271

Mitre link : CVE-2024-29271

CVE.ORG link : CVE-2024-29271


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')