PT-2024-21399 · Kirby Cms+1 · Kirby Cms+1
Published
2024-02-21
·
Updated
2025-08-21
·
CVE-2024-26482
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kirby CMS version 4.1.0
Description
An HTML injection issue exists in the Edit Content Layout module. The vendor disputes the significance of this report, stating that some HTML formatting is allowed and backend sanitization prevents the injection of malicious scripts. However, it is reported that this could allow attackers to execute arbitrary code via a crafted payload.
Recommendations
For Kirby CMS version 4.1.0, consider disabling the Edit Content Layout module until further guidance is available from the vendor, as a temporary workaround to minimize potential risks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kirby Cms
Suse