CVE-2024-26484
CVE-2024-26484 is a stored cross-site scripting (XSS) vulnerability affecting the Edit Content Layout module in Kirby CMS v4.1.0. This vulnerability allows attackers to inject malicious web scripts or HTML into the Link field, potentially compromising user accounts and data. While the vendor claims the issue only affected the trykirby.com demo site, unvalidated input in web applications is always a serious concern.
The stored XSS nature means the malicious script is permanently stored on the server, affecting users who access the compromised content. With an SVRS of 30, the threat is currently considered low. However, the risk of exploitation should not be ignored, especially if the vulnerability can be triggered on customer-controlled systems. Successful exploitation could lead to session hijacking and unauthorized access to sensitive information.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.