PT-2024-39137 · WordPress · Amcharts

Krzysztof Zając

·

Published

2024-09-12

·

Updated

2024-09-26

·

CVE-2024-8622

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: amCharts: Charts and Maps plugin for WordPress versions up to, and including, 1.4.4
Description: The issue allows unauthenticated attackers to inject arbitrary web scripts in pages through Reflected Cross-Site Scripting via the amcharts javascript parameter. This is possible due to the ability to supply arbitrary JavaScript and a lack of nonce validation on the preview functionality, making it possible for attackers to execute scripts if they can trick a user into performing an action such as clicking on a link.
Recommendations: For versions up to, and including, 1.4.4, update to a version that includes a fix for this issue to prevent Reflected Cross-Site Scripting attacks. As a temporary workaround, consider disabling the preview functionality that utilizes the amcharts javascript parameter until a patch is available. Restrict access to the vulnerable parameter to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-8622

Affected Products

Amcharts