CVE-2024-7127 HIGH

CVE-2024-7127: XSS in Stackposts - Social Marketing Tool

Vendor Stackposts
Product Social Marketing Tool
Weakness CWE-79 · XSS
Published July 30, 2024
Last update August 1, 2024

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:A/V:D/RE:L/U:Green

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cross-site Scripting (XSS) attack. By submitting the payload in the username during registration, it can be executed later in the application panel. This could lead to the unauthorised acquisition of information (e.g. cookies from a logged-in user). After multiple attempts to contact the vendor we did not receive any answer. Our team has confirmed the existence of this vulnerability. We suppose this issue affects Social Marketing Tool in all versions.

Key dates

02Disclosure timeline

July 30, 2024 CVE published
August 1, 2024 Record updated