CVE-2024-50810
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
08/11/2024
Last modified:
15/04/2026
Description
hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM



