PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirects
Vulnerability Description
PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a payload in the 'Redirect From' field to execute arbitrary JavaScript when administrators view the redirects page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58297
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- tmrswrr
Affected Vendor
Pyrocms
View all reports →