Vulnerability Description
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nodebb | Nodebb | 3.11.0 |
Related Weaknesses (CWE)
References
- http://nodebb.comProduct
- https://github.com/NodeBB/NodeBB/commit/4e69bff72fd04779064d37e46a43080e6c328adfPatch
- https://www.tonysec.com/posts/cve-2024-57041/ExploitThird Party Advisory
FAQ
What is CVE-2024-57041?
CVE-2024-57041 is a vulnerability with a CVSS score of 4.6 (MEDIUM). A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
How severe is CVE-2024-57041?
CVE-2024-57041 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57041?
Check the references section above for vendor advisories and patch information. Affected products include: Nodebb Nodebb.