PT-2024-18919 · Unknown · Livewire/Livewire

Dan Harrin

·

Published

2024-03-18

·

Updated

2024-03-19

·

CVE-2024-21504

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions livewire/livewire versions 3.3.5 through 3.4.9
Description The issue allows an attacker to inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it. This occurs when a page uses [Url] for a property.
Recommendations For versions 3.3.5 through 3.4.9, update to version 3.4.9 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-21504
GHSA-389C-CF87-QMWJ

Affected Products

Livewire/Livewire