cleantalk
Vulnerabilities and Security Researches

System Dashboard, CVE-2024-11107

CVE, Research URL

CVE-2024-11107

Application

System Dashboard

Published on
Dec 10, 2024
Research Description
The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
Affected versions
Min -, max 2.8.15.
Status
vulnerable