Security Advisory

CVE-2024-49296

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-10-17 19:05:35
Last updated 2026-04-28 16:10:24
Assigner Patchstack
State PUBLISHED

Description

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability in JC Custom Add to Cart Button Label and Link woo-custom-cart-button allows Stored XSS.This issue affects Custom Add to Cart Button Label and Link: from n/a through <= 1.6.1.