A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://drive.google.com/file/d/10BVQKYo2H1-Nx3FOGteL2xww4lbZ3xlS/view?usp=sharing | Exploit |
https://github.com/w3bn00b3r/Stored-Cross-Site-Scripting-XSS---Automad-2.0.0-alpha.4/ | Third Party Advisory Exploit |
Configurations
History
21 Apr 2025, 14:38
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:automad:automad:2.0.0:alpha4:*:*:*:*:*:* | |
First Time |
Automad
Automad automad |
|
References | () https://drive.google.com/file/d/10BVQKYo2H1-Nx3FOGteL2xww4lbZ3xlS/view?usp=sharing - Exploit | |
References | () https://github.com/w3bn00b3r/Stored-Cross-Site-Scripting-XSS---Automad-2.0.0-alpha.4/ - Third Party Advisory, Exploit |
23 Aug 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-23 21:15
Updated : 2025-04-21 14:38
NVD link : CVE-2024-40111
Mitre link : CVE-2024-40111
JSON object : View
Products Affected
automad
- automad
CWE
No CWE.