CVE-2024-48239

An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
CVSS

No CVSS.

References
Link Resource
https://github.com/taosir/wtcms/issues/16 Exploit Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:wtcms_project:wtcms:1.0:*:*:*:*:*:*:*

History

17 Apr 2025, 18:56

Type Values Removed Values Added
CPE cpe:2.3:a:wtcms_project:wtcms:1.0:*:*:*:*:*:*:*
First Time Wtcms Project wtcms
Wtcms Project
References () https://github.com/taosir/wtcms/issues/16 - () https://github.com/taosir/wtcms/issues/16 - Exploit, Third Party Advisory, Issue Tracking

25 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-25 22:15

Updated : 2025-04-17 18:56


NVD link : CVE-2024-48239

Mitre link : CVE-2024-48239


JSON object : View

Products Affected

wtcms_project

  • wtcms
CWE

No CWE.