Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fudforum | Fudforum | 3.1.3 |
Related Weaknesses (CWE)
References
- https://github.com/CrownZTX/vulnerabilities/blob/main/fudforum/stored_xss_in_admExploit
- https://github.com/CrownZTX/vulnerabilities/blob/main/fudforum/stored_xss_in_admExploit
FAQ
What is CVE-2024-30950?
CVE-2024-30950 is a vulnerability with a CVSS score of 3.5 (LOW). A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/a...
How severe is CVE-2024-30950?
CVE-2024-30950 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-30950?
Check the references section above for vendor advisories and patch information. Affected products include: Fudforum Fudforum.