1 results (0.004 seconds)
CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0
CVE-2024-42697
https://notcve.org/view.php?id=CVE-2024-42697
20 Sep 2024 — Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function. • https://github.com/JustDinooo/CVEs/blob/main/CVE-2024-42697/poc.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •