PT-2025-3176 · Unknown · Lemonade Social Networks Autoposter Pinterest

Mika

·

Published

2025-01-02

·

Updated

2025-01-07

·

CVE-2024-56028

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Lemonade Social Networks Autoposter Pinterest versions n/a through 2.0
Description The issue is related to improper neutralization of input during web page generation, which allows reflected Cross-site Scripting (XSS). This problem enables attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions on behalf of the user.
Recommendations For versions n/a through 2.0, consider disabling any functionality that allows user input to be reflected in web pages until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using parameters that could be used to inject malicious scripts in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-56028

Affected Products

Lemonade Social Networks Autoposter Pinterest