CVE-2024-6177: XSS vulnerability in LG SuperSign CMS
Published Jun 20, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
Affected Software
1 affected component
LG SuperSign CMS>=4.1.3<4.3.1
Event History
Jun 20, 2024
CVE Published
via MITRE·12:52 AM
Data Sourced
via MITRE·12:52 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6177?
CVE-2024-6177 is classified as a medium-severity reflected Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-6177?
To fix CVE-2024-6177, you should update your LG SuperSign CMS to version 4.3.1 or later.
3
Which versions of SuperSign CMS are affected by CVE-2024-6177?
CVE-2024-6177 affects LG SuperSign CMS versions from 4.1.3 up to, but not including, 4.3.1.
4
What type of vulnerability is CVE-2024-6177?
CVE-2024-6177 is an improper neutralization of input during web page generation, specifically a reflected XSS vulnerability.
5
Who is affected by CVE-2024-6177?
Organizations using affected versions of LG SuperSign CMS are at risk of exploitation due to CVE-2024-6177.