Description
OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which uses the affected product, when a user configures the profile with some malicious contents, an arbitrary script may be executed on the web browsers of other users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 27 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jan 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openpne
Openpne optimelineplugin |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:openpne:optimelineplugin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpne
Openpne optimelineplugin |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-03-27T14:25:32.763Z
Reserved: 2024-02-22T01:52:03.723Z
Link: CVE-2024-27278
Updated: 2024-08-02T00:27:59.908Z
Status : Modified
Published: 2024-03-06T00:15:52.817
Modified: 2025-03-27T15:15:51.007
Link: CVE-2024-27278
No data.
OpenCVE Enrichment
No data.
Weaknesses