Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37437


Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Cross-Site Scripting (XSS), Stored XSS.This issue affects Elementor Website Builder: from n/a through 3.22.1.


Published

2024-07-09T11:15:14.470

Last Modified

2024-11-21T09:23:50.810

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application elementor website_builder < 3.22.2 Yes

References