PT-2024-27156 · Unknown · Monstra Cms

Ools

·

Published

2024-06-07

·

Updated

2024-08-22

·

CVE-2024-36773

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Monstra CMS version 3.0.4
Description A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Themes parameter at "index.php".
Recommendations For Monstra CMS version 3.0.4, consider disabling the Themes parameter at "index.php" until a patch is available to prevent exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-36773

Affected Products

Monstra Cms