Intel

AIKIDO-2024-10022

livewire/livewire is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-21504 Published Apr 10, 2024

60

Medium Risk

This Affects:

phplivewire/livewire
3.3.5 - 3.4.8
Fixed in 3.4.9
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when a page uses #[Url] for a property. An attacker can inject HTML code into the user's browser session by crafting a malicious link and convincing the user to click on it.

Who does this affect?

You are affected if you are using a version of this package >= 3.3.5 and = 4.2.0.

Background info

livewire/livewire is vulnerable to Cross-site Scripting (XSS) in versions 3.3.5 - 3.4.8.

How to fix this

Upgrade the livewire/livewire library to the patch version.