CVE-2024-43225

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 12, 2024
Updated: Aug 13, 2024
CWE ID 79

Summary

CVE-2024-43225 is a newly disclosed vulnerability involving improper input neutralization during web page generation, specifically Stored Cross-site Scripting (XSS), in ThemeLooks Enter Addons. This issue impacts versions of the add-on from n/a up to and including 2.1.7. Successful exploitation of this flaw could allow attackers to inject malicious scripts into a victim's web page, potentially leading to account takeover, data theft, or other malicious activities. Users should immediately update their ThemeLooks Enter Addons to the latest patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share