PT-2024-23656 · Discuzx · Discuzx
Hebing123
·
Published
2024-04-11
·
Updated
2024-08-01
·
CVE-2024-30884
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Discuz! version X3.4 20220811
Description
The issue is a Reflected Cross-Site Scripting (XSS) vulnerability, which allows remote attackers to execute arbitrary code and obtain sensitive information. This is achieved via a crafted payload to the
primarybegin parameter in the "misc.php" component.Recommendations
For Discuz! version X3.4 20220811, consider disabling access to the
misc.php component or restricting the primarybegin parameter to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discuzx