A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-02-22T00:00:00
Updated: 2024-10-30T15:36:49.915Z
Reserved: 2024-02-12T00:00:00
Link: CVE-2024-25876
Vulnrichment
Updated: 2024-08-01T23:52:05.971Z
NVD
Status : Awaiting Analysis
Published: 2024-02-22T14:15:47.033
Modified: 2024-10-30T16:35:12.507
Link: CVE-2024-25876
Redhat
No data.