WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

Conversation

@Sourabh-Sahu
Copy link
Contributor

@Sourabh-Sahu Sourabh-Sahu commented Dec 5, 2025

Add CVE-2024-39646

Improper Neutralization of Input During Web Page Generation (XSS) in Custom 404 Pro <= 3.11.1.

  • Fixed CVE-2020-XXX / Added CVE-2020-XXX / Updated CVE-2020-XXX
  • References:

Template validation

  • Validated with a host running a vulnerable version and/or configuration (True Positive)
  • Validated with a host running a patched version and/or configuration (avoid False Positive)
$ nuclei -u https://192.168.2.180/wordpress -t CVE-2024-39646.yaml -var username=admin -var password=admin -debug

debug.txt

Additional References:

@Sourabh-Sahu Sourabh-Sahu changed the title Add CVE-2024-39646 Add CVE-2024-39646 (Updated CVEs) Dec 5, 2025
@github-actions github-actions bot requested a review from pussycat0x December 5, 2025 10:32
@DhiyaneshGeek
Copy link
Member

Hi @Sourabh-Sahu

As part of the bounty program, we’re closing this report for the following reason: the submitted CVE requires prerequisite data to exploit. Our program scope only covers vulnerabilities that are fully unauthenticated and independently verifiable using JS and HTTP templates.

Thanks for the submission and understanding.

@DhiyaneshGeek DhiyaneshGeek added the Done Ready to merge label Dec 8, 2025
@DhiyaneshGeek DhiyaneshGeek reopened this Dec 8, 2025
@DhiyaneshGeek DhiyaneshGeek removed the Done Ready to merge label Dec 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants