Medium severity4.8NVD Advisory· Published Oct 25, 2024· Updated Jun 17, 2026
CVE-2024-48239
CVE-2024-48239
Description
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WTCMS/WTCMSdescription
- cpe:2.3:a:wtcms_project:wtcms:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/taosir/wtcms/issues/16nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.