VDB
CVE-2024-49606
CVE-2024-49606
PUBLISHED
CVSS 7.099999904632568 HIGH
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dotsquares Google Map Locations allows Reflected XSS.This issue affects Google Map Locations: from n/a through 1.0.
EPSS 0.27% · 19.8th percentile
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score
0.27%
19.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dotsquares | Google Map Locations | n/a |
| DotsquaresLtd | Google Map Locations | 0 |
| dotsquares | google_map_locations | 0, 0 |
Timeline
- Oct 20, 2024 Coalition ESS Score
- Oct 20, 2024 CVE Published
- Oct 20, 2024 PoC Published
- Oct 21, 2024 EPSS Score
- Oct 21, 2024 Coalition ESS Score
- Oct 23, 2024 Coalition ESS Score
- Nov 9, 2024 EPSS Score
- Nov 15, 2024 Coalition ESS Score
- Nov 27, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
- Jan 5, 2025 EPSS Score
- Jan 24, 2025 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-49606 advisory
- https://patchstack.com/database/Wordpress/Plugin/google-map-locations/vulnerability/wordpress-google-map-locations-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve url
- https://patchstack.com/database/vulnerability/google-map-locations/wordpress-google-map-locations-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve url