Zadarma · Zadarma Extension · CVE-2024-22880
Name of the Vulnerable Software and Affected Versions:
Zadarma Zadarma extension version 1.0.11
Description:
The issue allows a remote attacker to execute arbitrary code via a crafted script to the webchat component. This is a Cross Site Scripting vulnerability.
Recommendations:
For Zadarma Zadarma extension version 1.0.11, consider disabling the webchat component until a patch is available to prevent exploitation. Restrict access to the webchat component to minimize the risk of arbitrary code execution.