CVE-2024-32578Cross-site Scripting in Slider

Severity
6.1MEDIUMNVD
CNA7.1
EPSS
1.4%
top 19.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This issue affects Slider by 10Web: from n/a through 1.2.54.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVD10web/slider< 1.2.55
CVEListV510web/slider_by_10webn/a1.2.54

🔴Vulnerability Details

2
CVEList
WordPress Sliderby10Web plugin <= 1.2.54 - Cross Site Scripting (XSS) vulnerability2024-04-18
GHSA
GHSA-qx47-rwwf-w92p: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS2024-04-18