CVE-2024-38785
Jegstudio
CVE-2024-38785 is a Stored XSS (Cross-Site Scripting) vulnerability in the Jegstudio Gutenverse plugin, affecting versions up to 1.9.2. This vulnerability allows attackers to inject malicious scripts into web pages, potentially compromising user data and session information. While the CVSS score is 5.4, the SOCRadar Vulnerability Risk Score (SVRS) is 53, indicating a moderate risk level that needs prompt attention. The vulnerability resides in the improper neutralization of input during web page generation, making it susceptible to CWE-79 attacks. Successful exploitation could lead to unauthorized access, data theft, or defacement of the website. Given the plugin's widespread use, patching to a secure version is highly recommended to mitigate potential risks and ensure website security. Despite not being classified as critical by SVRS, proactive measures are necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.