
Cloud Vulnerability DB
A community-led vulnerabilities database
An HTML injection vulnerability was discovered in the Edit Content Layout module of Kirby CMS version 4.1.0. The vulnerability was reported and assigned CVE-2024-26482. However, the vendor has disputed the significance of this report, noting that while HTML formatting (such as H1 elements) is allowed, backend sanitization prevents the execution of malicious scripts (NVD).
The vulnerability has been assigned a CVSS 3.1 Base Score of 7.1 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H by CISA-ADP. The vulnerability is classified under CWE-80, which refers to 'Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)' (NVD).
The potential impact of this vulnerability appears to be limited due to the backend sanitization measures in place. While HTML formatting is permitted, the system's security controls prevent the execution of malicious scripts, as stated in the vendor's dispute (NVD).
Given that this is a disputed vulnerability with built-in backend sanitization measures, no specific mitigation steps have been published. The vendor maintains that their existing security controls adequately protect against malicious script execution (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."