← Back

CVE-2024-8239

nvd nist
Published: Sep 30, 2024Modified: Oct 7, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.

Affected (1)

Products: Squirrly: Starbox
1 product
Starbox
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.5.3

References (1)

Source: contact@wpscan.com
ExploitThird Party Advisory

Timeline

No history available yet.