Record summary

CVE-2024-43971 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.5.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 28, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 3.2.5affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMSunshine Photo Cart <= 3.2.5 - Reflected Cross-Site ScriptingCVSS 6.1

WP Sunshine Sunshine Photo Cart versions up to 3.2.5 contain a reflected cross-site scripting caused by improper input neutralization during web page generation, letting attackers execute malicious scripts in users' browsers, exploit requires attacker to craft malicious input.

Impact

Attackers can execute malicious scripts in users' browsers, potentially stealing cookies, session tokens, or performing actions on behalf of users.

Remediation

Update to Sunshine Photo Cart version 3.2.6 or later.

WeaknessesCWE-79
Authors0xanis
Template tagscvecve2024wordpresswp-scanwp-pluginxsssunshine-photo-cartauthenticatedvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3