PT-2024-23656 · Discuzx · Discuzx

Hebing123

·

Published

2024-04-11

·

Updated

2024-08-01

·

CVE-2024-30884

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Discuz! version X3.4 20220811
Description The issue is a Reflected Cross-Site Scripting (XSS) vulnerability, which allows remote attackers to execute arbitrary code and obtain sensitive information. This is achieved via a crafted payload to the primarybegin parameter in the "misc.php" component.
Recommendations For Discuz! version X3.4 20220811, consider disabling access to the misc.php component or restricting the primarybegin parameter to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-30884

Affected Products

Discuzx