ZeroHour

CVE-2024-29271

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p45
Published
()
Modified
Description

Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.

Vendors
vvveb
Products
vvvebjs
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.