CVE-2024-38744

Publication date

2024-11-01 14:18:01

Family

Patchstack

State

PUBLISHED

Description

Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0.