Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Cosmetsy theme (core plugin), KlbTheme Partdo theme (core plugin), KlbTheme Bacola theme (core plugin), KlbTheme Medibazar theme (core plugin), KlbTheme Furnob theme (core plugin), KlbTheme Clotya theme (core plugin) allows Reflected XSS.This issue affects Cosmetsy theme (core plugin): from n/a through 1.3.0; Partdo theme (core plugin): from n/a through 1.0.9; Bacola theme (core plugin): from n/a through 1.3.3; Medibazar theme (core plugin): from n/a through 1.2.3; Furnob theme (core plugin): from n/a through 1.1.7; Clotya theme (core plugin): from n/a through 1.1.5.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-03-26T07:57:39.488Z

Updated: 2024-08-06T18:32:35.120Z

Reserved: 2023-11-30T17:12:29.821Z

Link: CVE-2023-49839

cve-icon Vulnrichment

Updated: 2024-08-02T22:01:26.217Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-26T08:15:35.343

Modified: 2024-11-21T08:33:56.183

Link: CVE-2023-49839

cve-icon Redhat

No data.