CVE-2024-22288
27.03.2024, 06:15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.4.0.
Vendor | Product | Version |
---|---|---|
webtoffee | woocommerce_pdf_invoices\,_packing_slips\,_delivery_notes_and_shipping_labels | 𝑥 < 4.4.1 |
𝑥
= Vulnerable software versions
References