CVE-2024-57277
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
24/01/2025
Last modified:
05/02/2025
Description
InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM