CVE-2024-33916
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published May 3, 2024
CWE ID 79
Summary
CVE-2024-33916 is a Cross-site Scripting (XSS) vulnerability affecting the MachoThemes CPO Companion. The flaw involves improper neutralization of user input during web page generation, allowing an attacker to inject malicious scripts into the affected platform. This stored XSS vulnerability can be exploited to steal user data, launch phishing attacks, or carry out other malicious activities. The issue affects versions of CPO Companion from n/a through 1.1.0. Users are urged to apply the necessary patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.