Unknown · Monstra Cms · CVE-2024-36773
**Name of the Vulnerable Software and Affected Versions**
Monstra CMS version 3.0.4
**Description**
A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the `Themes` parameter at "index.php".
**Recommendations**
For Monstra CMS version 3.0.4, consider disabling the `Themes` parameter at "index.php" until a patch is available to prevent exploitation.