PT-2024-21399 · Kirby Cms+1 · Kirby Cms+1

Published

2024-02-21

·

Updated

2025-08-21

·

CVE-2024-26482

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kirby CMS version 4.1.0
Description An HTML injection issue exists in the Edit Content Layout module. The vendor disputes the significance of this report, stating that some HTML formatting is allowed and backend sanitization prevents the injection of malicious scripts. However, it is reported that this could allow attackers to execute arbitrary code via a crafted payload.
Recommendations For Kirby CMS version 4.1.0, consider disabling the Edit Content Layout module until further guidance is available from the vendor, as a temporary workaround to minimize potential risks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-26482
GHSA-QV4X-V2V4-F8P9
SUSE-SU-2024:2571-1

Affected Products

Kirby Cms
Suse