Skip to content

Cross-site scripting (XSS) vulnerability in open link functionality

High
mlewand published GHSA-rhxf-gvmh-hrxm Jun 14, 2024

Package

No package listed

Affected versions

<1.0.5

Patched versions

1.0.5

Description

Impact

The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < 1.0.5.

Patches

The problem has been recognized and patched. The fix is available starting with version 1.0.5.

Acknowledgements

I would like to thank Anurag Mondal for recognizing and reporting this vulnerability.

References: https://github.com/7Ragnarok7/CVE-2024-37888/blob/main/README.md

Severity

High

CVE ID

CVE-2024-37888

Weaknesses

No CWEs