CVE-2024-40111

A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.
Configurations

Configuration 1 (hide)

cpe:2.3:a:automad:automad:2.0.0:alpha4:*:*:*:*:*:*

History

21 Apr 2025, 14:38

Type Values Removed Values Added
References () https://drive.google.com/file/d/10BVQKYo2H1-Nx3FOGteL2xww4lbZ3xlS/view?usp=sharing - () https://drive.google.com/file/d/10BVQKYo2H1-Nx3FOGteL2xww4lbZ3xlS/view?usp=sharing - Exploit
References () https://github.com/w3bn00b3r/Stored-Cross-Site-Scripting-XSS---Automad-2.0.0-alpha.4/ - () https://github.com/w3bn00b3r/Stored-Cross-Site-Scripting-XSS---Automad-2.0.0-alpha.4/ - Third Party Advisory, Exploit
CPE cpe:2.3:a:automad:automad:2.0.0:alpha4:*:*:*:*:*:*
First Time Automad
Automad automad

Information

Published : 2024-08-23 21:15

Updated : 2025-04-21 14:38


NVD link : CVE-2024-40111

Mitre link : CVE-2024-40111

CVE.ORG link : CVE-2024-40111


JSON object : View

Products Affected

automad

  • automad
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')