CVE-2024-50810

h

opetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.

Configurations

No configuration.

History

21 Nov 2024, 09:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79

12 Nov 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) hopetree izone lts c011b48 contiene una vulnerabilidad de tipo Cross Site Scripting (XSS) en la función de comentarios de artículos. En \apps\comment\views.py, AddCommintView() no filtra de forma segura la entrada del usuario y la muestra directamente en la página de interfaz a través de plantillas.

08 Nov 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-08 19:15

Updated : 2024-11-21 09:44


NVD link : CVE-2024-50810

Mitre link : CVE-2024-50810

CVE.ORG link : CVE-2024-50810


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')