CVE-2024-47621

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 5, 2024
CWE ID 79

Summary

CVE-2024-47621 is a Cross-site Scripting (XSS) vulnerability identified in the Zotpress plugin, affecting versions up to 7.3.10. This vulnerability allows for Stored XSS attacks, which can be exploited by attackers if user interaction occurs, posing a medium risk to organizations that utilize affected products. Remediation involves updating to the latest version of Zotpress to mitigate the risk associated with this vulnerability. The attack vector requires low privileges and is considered to have low integrity and confidentiality impacts, although the potential for exploitation remains due to user interaction requirements. For further details and patch information, resources are available from Patchstack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share