PT-2024-23487 · Unknown · Aesop Story Engine

Lvt-Tholv2K

·

Published

2024-03-31

·

Updated

2024-04-01

·

CVE-2024-30557

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Aesop Story Engine versions prior to 2.3.3
Description The issue is related to improper neutralization of input during web page generation, which leads to a Stored XSS vulnerability. This allows for the storage of malicious scripts in the application, which can then be executed by other users.
Recommendations For versions prior to 2.3.3, update to version 2.3.3 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-30557

Affected Products

Aesop Story Engine