CVE-2024-48239

An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
References
Link Resource
https://github.com/taosir/wtcms/issues/16 Exploit Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:wtcms_project:wtcms:1.0:*:*:*:*:*:*:*

History

17 Apr 2025, 18:56

Type Values Removed Values Added
References () https://github.com/taosir/wtcms/issues/16 - () https://github.com/taosir/wtcms/issues/16 - Exploit, Third Party Advisory, Issue Tracking
CPE cpe:2.3:a:wtcms_project:wtcms:1.0:*:*:*:*:*:*:*
First Time Wtcms Project wtcms
Wtcms Project

29 Oct 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-79

28 Oct 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en WTCMS 1.0. En el método plupload en \AssetController.class.php, los parámetros de la aplicación no se procesan, lo que genera un ataque de Cross Site Scripting (XSS).

25 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-25 22:15

Updated : 2025-04-17 18:56


NVD link : CVE-2024-48239

Mitre link : CVE-2024-48239

CVE.ORG link : CVE-2024-48239


JSON object : View

Products Affected

wtcms_project

  • wtcms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')