CVE-2024-30194
WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-30194 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Sunshine Photo CartBrowse sunshinephotocart / Sunshine Photo CartDefault status: unaffected | CVE List | Through 3.1.1 | affected |
sunshine_photo_cartBrowse sunshinephotocart / sunshine_photo_cart | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMSunshine Photo Cart <= 3.1.1 - Reflected Cross-Site ScriptingCVSS 6.1
WP Sunshine Sunshine Photo Cart versions up to 3.1.1 contain a cross-site scripting caused by improper neutralization of input during web page generation, letting attackers execute malicious scripts in users' browsers, exploit requires attacker to craft malicious input.
Impact
Attackers can execute malicious scripts in users' browsers, leading to session hijacking, defacement, or redirection.
Remediation
Update to the latest version of Sunshine Photo Cart.
Source: ProjectDiscovery