Record summary

CVE-2024-30194 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 25, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 3.1.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMSunshine Photo Cart <= 3.1.1 - Reflected Cross-Site ScriptingCVSS 6.1

WP Sunshine Sunshine Photo Cart versions up to 3.1.1 contain a cross-site scripting caused by improper neutralization of input during web page generation, letting attackers execute malicious scripts in users' browsers, exploit requires attacker to craft malicious input.

Impact

Attackers can execute malicious scripts in users' browsers, leading to session hijacking, defacement, or redirection.

Remediation

Update to the latest version of Sunshine Photo Cart.

WeaknessesCWE-79
Authors0xanis
Template tagscvecve2024wordpresswp-pluginxsssunshine-photo-cartauthenticatedvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3