Lucene search

K
nvd[email protected]NVD:CVE-2024-45625
HistorySep 09, 2024 - 5:15 a.m.

CVE-2024-45625

2024-09-0905:15:01
CWE-79
web.nvd.nist.gov
1
cross-site scripting
forminator
vulnerability
web browser
crafted url
web form.

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.0%

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.

Affected configurations

Nvd
Node
incsubforminatorRange<1.34.1wordpress
VendorProductVersionCPE
incsubforminator*cpe:2.3:a:incsub:forminator:*:*:*:*:*:wordpress:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.0%

Related for NVD:CVE-2024-45625