VDB
CVE-2024-49335
CVE-2024-49335
PUBLISHED
CVSS 7.099999904632568 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Edush Maxim GoogleDrive folder list allows Stored XSS.This issue affects GoogleDrive folder list: from n/a through 2.2.2.
EPSS 0.16% · 5.7th percentile
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score
0.16%
5.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| edush_maxim | googledrive_folder_list | 0, 0 |
| sh4d0w28 | GoogleDrive folder list | 0 |
| Edush Maxim | GoogleDrive folder list | n/a |
Timeline
- Oct 20, 2024 Coalition ESS Score
- Oct 20, 2024 CVE Published
- Oct 20, 2024 PoC Published
- Oct 21, 2024 EPSS Score
- Oct 21, 2024 Coalition ESS Score
- Oct 24, 2024 Coalition ESS Score
- Oct 29, 2024 Coalition ESS Score
- Nov 8, 2024 Coalition ESS Score
- Nov 9, 2024 EPSS Score
- Nov 27, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
- Jan 4, 2025 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-49335 advisory
- https://patchstack.com/database/Wordpress/Plugin/googledrive-folder-list/vulnerability/wordpress-googledrive-folder-list-plugin-2-2-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve url
- https://patchstack.com/database/vulnerability/googledrive-folder-list/wordpress-googledrive-folder-list-plugin-2-2-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve url