PT-2026-79835 · Unknown · Page Builder Ck
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Page Builder CK versions prior to 3.6.5
Description
Page Builder CK is subject to reflected Cross-Site Scripting (XSS), a flaw where malicious scripts are reflected off a web application to the user's browser. This occurs through the
iscontenttype parameter.Recommendations
Update Page Builder CK to version 3.6.5 or later.
Avoid using the
iscontenttype parameter until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Page Builder Ck