Medium severity6.1NVD Advisory· Published Mar 22, 2024· Updated Jun 17, 2026
CVE-2024-29271
CVE-2024-29271
Description
Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
vvvebjsnpm | < 1.7.5 | 1.7.5 |
Affected products
3- VvvebJs/VvvebJsdescription
Patches
Vulnerability mechanics
References
4- github.com/givanz/VvvebJs/commit/c0c0545b44b23acc288ef907fb498ce15b9b576envdPatchWEB
- github.com/givanz/VvvebJs/issues/342nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-pc95-3wgm-x28pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-29271ghsaADVISORY
News mentions
0No linked articles in our index yet.