CVE-2024-7354
Ninja Forms 3.8.6-3.8.10 - Reflected XSS
Record summary
CVE-2024-7354 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Ninja FormsDefault status: unaffected | CVE List | 3.8.6 to < 3.8.11 | affected |
ninja_formsBrowse ninjaforms / ninja_formsDefault status: unknown | CVE List | Before 3.8.11 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMNinja Forms 3.8.6-3.8.10 - Cross-Site ScriptingCVSS 6.1
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Impact
Attackers can potentially exploit this vulnerability to gain unauthorized access to sensitive information.
Remediation
Update the plugin to Latest version. Fixed in 3.8.11.
Source: ProjectDiscovery