CVE-2024-8717

PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip <= 2.3.32 - Reflected Cross-Site Scripting

The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pdf_source' parameter in all versions up to, and including, 2.3.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.


We have discovered 20,005 live websites that are affected by CVE-2024-8717.

Test my site




Affected Software

Product  3d Flipbook Dflip Lite
Category Wordpress Plugins
Vulnerable Domains20,005 live websites (37.30% of 3d Flipbook Dflip Lite install base)
Vulnerable Versions
  • from 0 through 2.3.32
Vulnerable Versions Count59 versions ( 89.39% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 24, 2024
  • Updated - Oct 24, 2024

Credits

  • Noah Stead (finder)

CVE-2024-8717 usage by Country

United States5,199 websites



Germany2,598 websites
France1,389 websites
Italy832 websites
GB705 websites
Turkey593 websites
Poland473 websites
Spain470 websites
Cyprus441 websites
Japan422 websites

CVE-2024-8717 usage by TLD

.com6,682 websites
.org1,377 websites
.de1,140 websites
.it703 websites
.fr469 websites
.com.br439 websites
.co.uk419 websites
.net370 websites
.nl362 websites
.pl341 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8717

Top websites that are affected by CVE-2024-8717. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States*,***
********.de Germany**,***
******.com United States**,***
******************.org United States**,***
***********.org United States**,***
**********.**.uk United States**,***
**********.com United States**,***
***.gr United States**,***
*******.com France**,***
**************.com Netherlands**,***
See full domain list

FAQ

CVE-2024-8717 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in 3d Flipbook Dflip Lite
A total of 20,005 websites have been identified as vulnerable to CVE-2024-8717, discovered through global website indexing conducted by WebTechSurvey.
3d Flipbook Dflip Lite is susceptible to CVE-2024-8717 vulnerability.
3d Flipbook Dflip Lite versions before, and including, 2.3.32 are vulnerable to CVE-2024-8717.