PT-2024-21966 · Unknown · Genesis Blocks

Dmitry Ignatyev

·

Published

2024-04-03

·

Updated

2024-07-03

·

CVE-2024-2761

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Genesis Blocks versions prior to 3.1.3
Description The issue allows attackers to conduct Stored XSS attacks by exploiting improperly escaped data input in some of the plugin's blocks, potentially enabling them to create admin accounts via crafted posts. This can be achieved with at least contributor privileges.
Recommendations For Genesis Blocks versions prior to 3.1.3, update to version 3.1.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable blocks to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2761

Affected Products

Genesis Blocks