
🔴 YesWiki, Stored XSS, #CVE-2024-34722 (Critical) https://dailycve.com/yeswiki-stored-xss-cve-2024-34722-critical/
Post summary
The tweet announces a critical stored XSS vulnerability in YesWiki (CVE-2024-34722) and links to a detailed article.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
4 versions affected across 1 product

🔴 YesWiki, Stored XSS, #CVE-2024-34722 (Critical) https://dailycve.com/yeswiki-stored-xss-cve-2024-34722-critical/
Post summary
The tweet announces a critical stored XSS vulnerability in YesWiki (CVE-2024-34722) and links to a detailed article.
4 of 4 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| OS | android | 12.0 | - | - | |
| OS | android | 12.1 | - | - | |
| OS | android | 13.0 | - | - | |
| OS | android | 14.0 | - | - |