CVE-2024-29271

Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:vvveb:vvvebjs:*:*:*:*:*:*:*:*

History

28 May 2025, 18:44

Type Values Removed Values Added
References () https://github.com/givanz/VvvebJs/commit/c0c0545b44b23acc288ef907fb498ce15b9b576e - () https://github.com/givanz/VvvebJs/commit/c0c0545b44b23acc288ef907fb498ce15b9b576e - Patch
References () https://github.com/givanz/VvvebJs/issues/342 - () https://github.com/givanz/VvvebJs/issues/342 - Exploit, Third Party Advisory, Issue Tracking
CPE cpe:2.3:a:vvveb:vvvebjs:*:*:*:*:*:*:*:*
First Time Vvveb vvvebjs
Vvveb

22 Mar 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-22 04:15

Updated : 2025-05-28 18:44


NVD link : CVE-2024-29271

Mitre link : CVE-2024-29271


JSON object : View

Products Affected

vvveb

  • vvvebjs
CWE

No CWE.