CVE-2024-27278
EUVD-2024-2451706.03.2024, 00:15
OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which uses the affected product, when a user configures the profile with some malicious contents, an arbitrary script may be executed on the web browsers of other users.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openpne | optimelineplugin | 𝑥 ≤ 1.2.11 |
𝑥
= Vulnerable software versions