Lucene search

K
nvd[email protected]NVD:CVE-2024-43999
HistorySep 18, 2024 - 12:15 a.m.

CVE-2024-43999

2024-09-1800:15:09
CWE-79
web.nvd.nist.gov
3
cve-2024-43999
xss
vulnerability
ninja forms

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

14.7%

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11.

Affected configurations

Nvd
Node
ninjaformsninja_formsRange<3.8.12wordpress
VendorProductVersionCPE
ninjaformsninja_forms*cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

14.7%

Related for NVD:CVE-2024-43999