Description
Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 20 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leotheme
Leotheme leo Product Search Module |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:leotheme:leo_product_search_module:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Leotheme
Leotheme leo Product Search Module |
|
| Metrics |
cvssV3_1
|
Fri, 20 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-20T17:53:35.608Z
Reserved: 2024-08-05T00:00:00.000Z
Link: CVE-2024-42697
Updated: 2024-09-20T17:50:44.528Z
Status : Awaiting Analysis
Published: 2024-09-20T18:15:04.390
Modified: 2024-09-26T13:32:55.343
Link: CVE-2024-42697
No data.
OpenCVE Enrichment
No data.
Weaknesses