PT-2024-28600 · Unknown · Kubio Ai Page Builder

João Pedro S Alcântara

·

Published

2024-08-01

·

Updated

2024-08-02

·

CVE-2024-39661

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kubio AI Page Builder versions 2.2.4 and earlier
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for potential malicious script injection into web pages generated by the affected software.
Recommendations For versions 2.2.4 and earlier, update to a version that contains a fix for this issue, if available. As a temporary workaround, consider restricting user input to minimize the risk of exploitation. Avoid using potentially vulnerable features in the Kubio AI Page Builder until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-39661

Affected Products

Kubio Ai Page Builder