What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBase Tables custom-database-tables allows Reflected XSS.This issue affects Custom DataBase Tables: from n/a through <= 2.1.34.
Explanation of Vulnerability in Simple Terms
02Summary
Custom DataBase Tables versions 2.1.34 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit an affected page. The vulnerability requires user interaction and can affect other users or site functionality. Update to a version newer than 2.1.34 to remediate.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in a victim's browser, potentially stealing session data or performing actions on their behalf.
Potential impact on your site
04Site Impact
Site visitors can be compromised; attackers may steal admin sessions or deface content without needing to log in.
Conditions required to exploit
05Prerequisites
Victim must visit a page containing the attacker's malicious input; no authentication required.
Key dates
06Disclosure timeline
January 9, 2025
CVE published
April 28, 2026
Record updated