ZeroHour

CVE-2024-30884

PoC
CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
Description

Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and obtain sensitive information via crafted payload to the primarybegin parameter in the misc.php component.

Vendors
discuz
Products
discuzx
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.