Vulnerability Description
PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a payload in the 'Redirect From' field to execute arbitrary JavaScript when administrators view the redirects page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pyrocms | Pyrocms | 3.0.1 |
Related Weaknesses (CWE)
References
- https://pyrocms.com/Product
- https://www.exploit-db.com/exploits/52016ExploitVDB Entry
- https://www.softaculous.com/apps/cms/PyroCMS/Product
- https://www.vulncheck.com/advisories/pyrocms-v-stored-cross-site-scripting-via-aThird Party Advisory
FAQ
What is CVE-2024-58297?
CVE-2024-58297 is a vulnerability with a CVSS score of 5.4 (MEDIUM). PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a payload in the 'Redir...
How severe is CVE-2024-58297?
CVE-2024-58297 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-58297?
Check the references section above for vendor advisories and patch information. Affected products include: Pyrocms Pyrocms.