github.com
https://github.com/livewire/livewire CVE-2024-21504
MEDIUM
Cross-site Scripting in livewire/livewire
Record summary
CVE-2024-21504 has a selected CVSS score of 6.1 (medium).
Description
Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 27, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
livewireBrowse laravel / livewireDefault status: unknown | CVE List | 3.3.5 to < 3.4.9 | affected |
livewire/livewire | CVE List | 3.3.5 to < 3.4.9 | affected |
livewire/livewireBrowse Packagist / livewire/livewire | GitHub Advisory | 3.3.5 to < 3.4.9 · Fixed in 3.4.9 | affected |
References
6github.com
https://github.com/livewire/livewire/commit/c65b3f0798ab2c9338213ede3588c3cdf4e6fcc0 github.com
https://github.com/livewire/livewire/pull/8117 github.com
https://github.com/livewire/livewire/releases/tag/v3.4.9 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-21504 security.snyk.io
https://security.snyk.io/vuln/SNYK-PHP-LIVEWIRELIVEWIRE-6446222