PT-2024-20630 · Codepeople · Codepeople Cp Polls

Kyle Sanchez

·

Published

2024-05-17

·

Updated

2024-05-17

·

CVE-2024-24874

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CodePeople CP Polls versions 1.0.71 and earlier
Description The issue is related to an Improper Neutralization of Script-Related HTML Tags in a Web Page, also known as Basic XSS, which allows Code Injection. This means that an attacker could potentially inject malicious code into a web page, leading to various security issues.
Recommendations For CodePeople CP Polls versions 1.0.71 and earlier, as a temporary workaround, consider disabling any functionality that allows user input to be directly injected into web pages until a patch is available. Restrict access to sensitive areas of the web application to minimize the risk of exploitation. Avoid using the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-24874

Affected Products

Codepeople Cp Polls