PT-2024-23690 · Htmly · Htmly

Published

2024-04-17

·

Updated

2025-08-21

·

CVE-2024-30953

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Htmly version 2.9.5
Description A stored cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link Name parameter of the Menu Editor module.
Recommendations For Htmly version 2.9.5, consider disabling the Menu Editor module until a patch is available to prevent exploitation of the stored XSS issue. Restrict access to the Link Name parameter to minimize the risk of arbitrary web script execution. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-30953

Affected Products

Htmly