CVE-2024-32961
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 25, 2024
CWE ID 79
Summary
CVE-2024-32961 is a Cross-site Scripting (XSS) vulnerability affecting Creative Themes HQ Blocksy, specifically versions from n/a to 2.0.33. This issue enables attackers to inject malicious code into a webpage, which can be stored and executed whenever the vulnerable page is accessed. By exploiting this Improper Neutralization of Input during Web Page Generation flaw, attackers can steal user data or take control of user sessions, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share