momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2024-12878: Lazy Blocks <= 3.8.2 - Cross-Site Scripting

CVE: CVE-2024-12878
CNVD: 暂无
CNNVD: 暂无
漏洞类型: XSS
漏洞等级: 高危
年份: 2026
POC_ID: 暂无
漏洞描述
Custom Block Builder WordPress plugin < 3.8.3 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before output, letting attackers execute malicious scripts in high privilege users' browsers, exploit requires victim to load malicious page. [已公开] id: CVE-2024-12878 info: name: Lazy Blocks <= 3.8.2 - Cross-Site Scripting author: Shivam Kamboj severity: medium description: | Custom Block Builder WordPress plugin < 3.8.3 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before output, letting attackers execute malicious scripts in high privilege users' browsers, exploit requires victim to load malicious page. impact: | Attackers can execute malicious scripts in high privilege users' browsers, potentially leading to session hijacking or account compromise. remediation: | Update to version 3.8.3 or later. reference: - https://wpscan.com/vulnerability/827444d1-87cb-4057-827a-d802eac82cf8/ - https://nvd.nist.gov/vuln/detail/CVE-2024-12878 metadata: verified: true max-request: 2 tags: cve,cve2024,wordpress,wp,wp-plugin,lazy-blocks,xss,reflected,authenticated flow: http(1) && http(2) http: - r
影响范围
未知
漏洞详情
登录后可查看漏洞详情。请先 登录注册
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无