CVE-2024-26472

KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' or 'validator' parameters of 'create-new-pwd.php'.
Configurations

Configuration 1 (hide)

cpe:2.3:a:msaad1999:klik_socialmediawebsite:1.0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-29 01:44

Updated : 2025-04-30 16:53


NVD link : CVE-2024-26472

Mitre link : CVE-2024-26472

CVE.ORG link : CVE-2024-26472


JSON object : View

Products Affected

msaad1999

  • klik_socialmediawebsite
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')