CVE-2024-47307

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 6, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-47307 is a newly discovered Cross-Site Scripting (XSS) vulnerability affecting the Meta slider and carousel with lightbox plugins. The flaw, which permits stored XSS attacks, resides in the way these plugins handle user input during web page generation. Hackers can exploit this weakness to inject malicious scripts into a targeted website, potentially compromising user data or taking control of the site. Versions from n/a to 2.0.1 of Meta slider and carousel with lightbox are reportedly vulnerable. It is crucial that users update to the latest, secure version of these plugins to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share