[CVE-2024-38454] ExpressionEngine, Version 7.3.15
bishopfox.com | vulnerability | CVE-2024-38454 | #xss | #vulnerability-disclosure | #open-redirect | #cms-security | #expressionengine | #cve-2024-38454
Summary
Bishop Fox identified two flaws in Packet Tide's ExpressionEngine 7.3.15, fixed in 7.4.11: unauthenticated XSS (CVE-2024-38454) and open HTTP redirection, which can yield Super Admin accounts.
- Published
- Collected
Skip to content