PT-2024-23656 · Discuzx · Discuzx

·

CVE-2024-30884

·

Published

2024-04-11

·

Updated

2024-08-01

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Discuz! version X3.4 20220811
Description The issue is a Reflected Cross-Site Scripting (XSS) vulnerability, which allows remote attackers to execute arbitrary code and obtain sensitive information. This is achieved via a crafted payload to the primarybegin parameter in the "misc.php" component.
Recommendations For Discuz! version X3.4 20220811, consider disabling access to the misc.php component or restricting the primarybegin parameter to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-30884

Affected Products

Discuzx